elastic / elastic/logstash

Security issues in parents layers

Open
#10,903 2 comments 1 reaction 0 assignees View on GitHub
docker
Dominant language
Java
Stars
14.9k
Forks
3.5k
Avg merge
1d 4h
Merged PRs (30d)
88

Description

There are security fix available for nss package build in parents layers:

```
{
"VulnerableFeaturesWithFix": [
{
"NamespaceName": "centos:7",
"Version": "3.28.4-11.el7_4",
"Name": "nss",
"AddedBy": "sha256:d9aaf4d82f249dc101a6638ff5177fe926cdebfa6c42d874dfa5029533da0e72",
"Vulnerabilities": [
{
"Severity": "High",
"NamespaceName": "centos:7",
"Link": "https://access.redhat.com/errata/RHSA-2017:2832",
"FixedBy": "3.28.4-12.el7_4",
"Description": "Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Security Fix(es): * A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running the application. (CVE-2017-7805) Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Martin Thomson as the original reporter.",
"Name": "RHSA-2017:2832"
}
]
},
{
"NamespaceName": "centos:7",
"Version": "3.28.4-11.el7_4",
"Name": "nss-tools",
"AddedBy": "sha256:d9aaf4d82f249dc101a6638ff5177fe926cdebfa6c42d874dfa5029533da0e72",
"Vulnerabilities": [
{
"Severity": "High",
"NamespaceName": "centos:7",
"Link": "https://access.redhat.com/errata/RHSA-2017:2832",
"FixedBy": "3.28.4-12.el7_4",
"Description": "Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Security Fix(es): * A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running the application. (CVE-2017-7805) Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Martin Thomson as the original reporter.",
"Name": "RHSA-2017:2832"
}
]
},
{
"NamespaceName": "centos:7",
"Version": "3.28.4-11.el7_4",
"Name": "nss-sysinit",
"AddedBy": "sha256:d9aaf4d82f249dc101a6638ff5177fe926cdebfa6c42d874dfa5029533da0e72",
"Vulnerabilities": [
{
"Severity": "High",
"NamespaceName": "centos:7",
"Link": "https://access.redhat.com/errata/RHSA-2017:2832",
"FixedBy": "3.28.4-12.el7_4",
"Description": "Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Security Fix(es): * A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running the application. (CVE-2017-7805) Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Martin Thomson as the original reporter.",
"Name": "RHSA-2017:2832"
}
]
}
],
"NotAnalysedLayers": []
}
```
Analysis from CoreOS Clair

Contributor guide

Open the contributing guide

Research direction

No repository file, test, or entry point is named. Start by locating the parent-layer definitions associated with the reported image digest and compare the NSS packages with RHSA-2017:2832. Done means the parent layers use the fixed NSS versions and a Clair scan no longer reports these vulnerabilities.

Written by the indexing model from the issue text.

Assessment

Tech stack
centos, docker
Domain
infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.