Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Instructions
Please try and perform pull requests against the
develop
branch.Merging against the master branch causes a new release to be deployed, and I'd like to avoid that on every PR.
PR Details
Fix CVE 2018 20843 by upgrading expat and dependencies
Description
Fix following scenned vulerabilities:
✗ Medium severity vulnerability found in e2fsprogs/libcom_err
Description: Out-of-bounds Write
Info: https://snyk.io/vuln/SNYK-ALPINE37-E2FSPROGS-493456
Introduced through: e2fsprogs/[email protected], krb5-conf/[email protected]
From: e2fsprogs/[email protected]
From: krb5-conf/[email protected] > krb5/[email protected] > e2fsprogs/[email protected]
Image layer: Introduced by your base image (python:3.6.8-alpine3.7)
Fixed in: 1.43.7-r1
✗ High severity vulnerability found in expat/expat
Description: XML External Entity (XXE) Injection
Info: https://snyk.io/vuln/SNYK-ALPINE37-EXPAT-453374
Introduced through: expat/[email protected], .python-rundeps@0, python2/[email protected], python3/[email protected]
From: expat/[email protected]
From: .python-rundeps@0 > expat/[email protected]
From: python2/[email protected] > expat/[email protected]
and 1 more...
Image layer: Introduced by your base image (python:3.6.8-alpine3.7)
Fixed in: 2.2.7-r0
✗ High severity vulnerability found in expat/expat
Description: Out-of-bounds Read
Info: https://snyk.io/vuln/SNYK-ALPINE37-EXPAT-489399
Introduced through: expat/[email protected], .python-rundeps@0, python2/[email protected], python3/[email protected]
From: expat/[email protected]
From: .python-rundeps@0 > expat/[email protected]
From: python2/[email protected] > expat/[email protected]
and 1 more...
Image layer: Introduced by your base image (python:3.6.8-alpine3.7)
Fixed in: 2.2.7-r1
✗ Critical severity vulnerability found in sqlite/sqlite-libs
Description: Out-of-bounds Read
Info: https://snyk.io/vuln/SNYK-ALPINE37-SQLITE-458200
Introduced through: sqlite/[email protected], .python-rundeps@0, python2/[email protected], python3/[email protected]
From: sqlite/[email protected]
From: .python-rundeps@0 > sqlite/[email protected]
From: python2/[email protected] > sqlite/[email protected]
and 1 more...
Image layer: Introduced by your base image (python:3.6.8-alpine3.7)
Fixed in: 3.25.3-r1
Related Issue
CVE-2018-20843