dotnet / dotnet/dotnet-docker

Vulnerabilities in the container image mcr.microsoft.com/dotnet/aspnet:8.0

Open
#5,217 1 comment 1 reaction 0 assignees View on GitHub
Dominant language
Dockerfile
Stars
4.9k
Forks
2k
Avg merge
1d 14h
Merged PRs (30d)
26

Description

We are using the Microsoft-provided Docker image called [mcr.microsoft.com/dotnet/aspnet:8.0](http://mcr.microsoft.com/dotnet/aspnet:8.0) in production. This is the current LTS image for the [ASP.NET](http://asp.net/) Core Runtime for .net 8.

Unfortunately, this image contains the following two vulnerabilities:

1. gnutls28, (A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust)

2. tar (GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump.)

3. systemd(A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.)

The vulnerabilities were found by the Prisma Cloud .

Would you be able to provide an update to this Docker image?

We rely on this image in production and need it urgently.

Please let me know if I can be of any assistance in resolving this issue.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.