Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

base Vulnerability - CVE-2023-4911 #1420

Closed
3 tasks done
ns-chsu opened this issue Oct 4, 2023 · 3 comments
Closed
3 tasks done

base Vulnerability - CVE-2023-4911 #1420

ns-chsu opened this issue Oct 4, 2023 · 3 comments

Comments

@ns-chsu
Copy link

ns-chsu commented Oct 4, 2023

  • I have read the SECURITY.md
  • I understand that this repo tracks debian package releases and cannot fix debian CVEs on its own
  • this CVE shows a fix is available in the appropriate debian version (buster, bullseye) and channel (main, security) and it has been more than 48 hours.

Please let me know the debian image to use which has the fix for the below CVE's
Image with base Vulnerability - gcr.io/distroless/base-debian11:nonroot
Image with base Vulnerability - gcr.io/distroless/base-debian12:nonroot
https://security-tracker.debian.org/tracker/CVE-2023-4911

@holistic-developer
Copy link

This will be fixed with with PR #1419

@sayeedhussain
Copy link

@holistic-developer Do you happen to know when this will be available here https://console.cloud.google.com/gcr/images/distroless/global/nodejs16-debian11

@loosebazooka
Copy link
Member

node16 is deprecated, use 18 or 20

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants