[ECR] Enhanced Scanning Vulnerability Bug on nginx-filesystem
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
Hi,
We have enabled enhanced scanning in our container and observed that the current module of the nginx-filesystem (nginx-filesystem-1.14.1-9.module+el8.0.0+4108+af250afe.noarch) was reported with multiple vulnerabilities (RHSA-2021:2259, RHSA-2021:2290, RHSA-2022:0323 and RHSA-2020:5495). Upon reaching out to the redhat security team, they have clarified that the nginx-filesystem is not directly affected by any vulnerabilities. Fixes from upstream do not impact the nginx-filesystem, so it is unlikely to have any security issues. I have attached our conversation with RedHat security team as proof that these vulnerabilities are not impacting the said module.
With this, AWS Team has been made aware of this concern and was advised to raise a bug through github to update the database.
[converstaionwithredhat.pdf](https://github.com/aws/containers-roadmap/files/12817131/converstaionwithredhat.pdf)
Contributor guide
Research direction
Review the reported nginx-filesystem version, vulnerability identifiers, and the attached Red Hat security conversation. No source files, tests, or entry points are named; the intended outcome is confirmation that ECR enhanced scanning no longer reports these vulnerabilities for nginx-filesystem.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nginx
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100