Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

This fails docker scout security scan #59

Open
hookenz opened this issue Oct 27, 2023 · 1 comment
Open

This fails docker scout security scan #59

hookenz opened this issue Oct 27, 2023 · 1 comment

Comments

@hookenz
Copy link

hookenz commented Oct 27, 2023

Due to using the old aws golang library instead of the v2 library this binary is vulnerable to the following CVEs

CVE-2020-8911⁠
CVE-2020-8912⁠

To fix it we need to upgrade to using github.com/aws/aws-sdk-go-v2

Affected version: all versions <= 1.1.1 (latest release).

@hookenz hookenz closed this as completed Dec 5, 2023
@hookenz hookenz reopened this Jan 9, 2024
@hookenz
Copy link
Author

hookenz commented Jan 9, 2024

As we use this library our docker image is flagged by docker scout.

I had a go at an upgrade by it's not trivial.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant