influxdata / influxdata/influxdata-docker
Chronograf 1.10.2 docker image critical vulnerability CVE-2023-45853
- Dominant language
- Shell
- Stars
- 364
- Forks
- 255
- Avg merge
- 3h 18m
- Merged PRs (30d)
- 7
Description
[aquasecurity/trivy](https://github.com/aquasecurity/trivy) reports that the latest Chronograf image (1.10.2) is impacted by:
- [CVE-2023-45853](https://avd.aquasec.com/nvd/cve-2023-45853) impacting Zlib (https://github.com/madler/zlib/issues/868)
Just making sure someone is aware of this since I see no mention of it in any previous issues.
Contributor guide
No contributing guide indexed for this repository
Research direction
No source file or test is named. Start by inspecting the Chronograf 1.10.2 Docker image build and reproducing the CVE-2023-45853 finding with Trivy; done means the affected zlib vulnerability is addressed and a follow-up scan confirms it.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker
- Domain
- devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100