Security issues in parents layers
- Dominant language
- Java
- Stars
- 14.9k
- Forks
- 3.5k
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 88
Description
There are security fix available for nss package build in parents layers:
```
{
"VulnerableFeaturesWithFix": [
{
"NamespaceName": "centos:7",
"Version": "3.28.4-11.el7_4",
"Name": "nss",
"AddedBy": "sha256:d9aaf4d82f249dc101a6638ff5177fe926cdebfa6c42d874dfa5029533da0e72",
"Vulnerabilities": [
{
"Severity": "High",
"NamespaceName": "centos:7",
"Link": "https://access.redhat.com/errata/RHSA-2017:2832",
"FixedBy": "3.28.4-12.el7_4",
"Description": "Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Security Fix(es): * A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running the application. (CVE-2017-7805) Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Martin Thomson as the original reporter.",
"Name": "RHSA-2017:2832"
}
]
},
{
"NamespaceName": "centos:7",
"Version": "3.28.4-11.el7_4",
"Name": "nss-tools",
"AddedBy": "sha256:d9aaf4d82f249dc101a6638ff5177fe926cdebfa6c42d874dfa5029533da0e72",
"Vulnerabilities": [
{
"Severity": "High",
"NamespaceName": "centos:7",
"Link": "https://access.redhat.com/errata/RHSA-2017:2832",
"FixedBy": "3.28.4-12.el7_4",
"Description": "Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Security Fix(es): * A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running the application. (CVE-2017-7805) Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Martin Thomson as the original reporter.",
"Name": "RHSA-2017:2832"
}
]
},
{
"NamespaceName": "centos:7",
"Version": "3.28.4-11.el7_4",
"Name": "nss-sysinit",
"AddedBy": "sha256:d9aaf4d82f249dc101a6638ff5177fe926cdebfa6c42d874dfa5029533da0e72",
"Vulnerabilities": [
{
"Severity": "High",
"NamespaceName": "centos:7",
"Link": "https://access.redhat.com/errata/RHSA-2017:2832",
"FixedBy": "3.28.4-12.el7_4",
"Description": "Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Security Fix(es): * A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running the application. (CVE-2017-7805) Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Martin Thomson as the original reporter.",
"Name": "RHSA-2017:2832"
}
]
}
],
"NotAnalysedLayers": []
}
```
Analysis from CoreOS Clair
Contributor guide
Research direction
No repository file, test, or entry point is named. Start by locating the parent-layer definitions associated with the reported image digest and compare the NSS packages with RHSA-2017:2832. Done means the parent layers use the fixed NSS versions and a Clair scan no longer reports these vulnerabilities.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- centos, docker
- Domain
- infrastructure, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100