Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to alpine 3.20.1 to fix CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366 #2116

Closed
dkwakkel opened this issue Jul 16, 2024 · 2 comments

Comments

@dkwakkel
Copy link

Alpine 3.20.1 which contains the fix for busybox CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366
(alpinelinux/docker-alpine#401) is a month ago released. When will the base image of node be updated to this version?

@SimenB SimenB closed this as not planned Won't fix, can't repro, duplicate, stale Jul 16, 2024
@dkwakkel
Copy link
Author

FYI: I checked the image, and saw it was using the right version of alpine and busybox which contains the fix. Still twistlock marks it is vulnerable.
Proabably given that on this page https://nvd.nist.gov/vuln/detail/CVE-2023-42366 it shows "affected configurations" as cpe:2.3:a:busybox:busybox:1.36.1:::::::* and thus twistlock still considers 1.36.1-r29 as vulnerable. Conclusion: false marked by twistlock as vulnerable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants