apache / apache/incubator-seata

使用最新镜像【seataio/seata-server:latest】被检测出大量安全漏洞,要怎么处理呢?

Open
#5,528 29 comments 0 reactions 0 assignees View on GitHub
good first issue Security task: help-wanted
Dominant language
Java
Stars
26k
Forks
8.8k
Avg merge
1d 8h
Merged PRs (30d)
4

Description

- [ ] I have searched the [issues](https://github.com/seata/seata/issues) of this repository and believe that this is not a duplicate.

### Ⅰ. Issue Description
使用Docker Hub上的seataio/seata-server:latest镜像被检测出大量安全漏洞
https://hub.docker.com/r/seataio/seata-server/tags

### Ⅱ. Describe what happened
seataio/seata-server:latest镜像存在292个漏洞
![image](https://user-images.githubusercontent.com/5292224/233815660-96703e6e-3610-44f0-80b7-c606d78e735b.png)

If there is an exception, please attach the exception trace:

```
Just paste your stack trace here!
```

### Ⅲ. Describe what you expected to happen
通过镜像部署seata后,上线安全测试检测出292个安全漏洞,涉及组件依赖,我们也不敢升级里面的组件

### Ⅳ. How to reproduce it (as minimally and precisely as possible)

1. 下载镜像
2. 使用trivy进行安全检测

Minimal yet complete reproducer code (or URL to code):

### Ⅴ. Anything else we need to know?

### Ⅵ. Environment:

- JDK version(e.g. `java -version`):
- Seata client/server version:
- Database version:
- OS(e.g. `uname -a`):
- Others:

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the seataio/seata-server:latest image on Docker Hub and the attached Trivy scan to identify what accounts for the 292 findings. Check the repository's image/build configuration and security policy before determining the upgrade scope. Done means the reported vulnerabilities are addressed or their impact and supported upgrade path are documented and validated.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, java
Domain
infrastructure, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.