influxdata / influxdata/influxdata-docker

Chronograf 1.10.2 docker image critical vulnerability CVE-2023-45853

Open
#715 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
Shell
Stars
364
Forks
255
Avg merge
3h 18m
Merged PRs (30d)
7

Description

[aquasecurity/trivy](https://github.com/aquasecurity/trivy) reports that the latest Chronograf image (1.10.2) is impacted by:

- [CVE-2023-45853](https://avd.aquasec.com/nvd/cve-2023-45853) impacting Zlib (https://github.com/madler/zlib/issues/868)

Just making sure someone is aware of this since I see no mention of it in any previous issues.

Contributor guide

No contributing guide indexed for this repository

Research direction

No source file or test is named. Start by inspecting the Chronograf 1.10.2 Docker image build and reproducing the CVE-2023-45853 finding with Trivy; done means the affected zlib vulnerability is addressed and a follow-up scan confirms it.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.