sitespeedio / sitespeedio/sitespeed.io
32 Critical CVEs in 41.3.3-plus1 sitespeedio Docker image - detected in the AWS ECR scans
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 5k
- Forks
- 624
- Avg merge
- 4h 8m
- Merged PRs (30d)
- 2
Description
Your question
Summary
We recently upgraded to 41.3.3 version and used sitespeedio/sitespeed.io 41.3.3-plus1 docker image for the same. As per my understanding the sitespeedio is built on Ubuntu 24.04 LTS (Noble) and the Ubuntu Noble package repository currently ships imagemagick 6.9.12.98+dfsg1-5.2build2, which is affected by 8 critical ImageMagick CVEs and 1 critical cJSON CVE - totalling 32 critical vulnerability rows in AWS ECR enhanced scanning.
We have applied a downstream OS patching layer (apt-get update && apt-get upgrade -y) on top of the upstream image which reduced the CVEs from 43 to 32, but this has no effect on the ImageMagick CVEs may be because Ubuntu Noble has not yet published the patched package in its security repository.
Please note: We were on sitespeedio version 37.4.1-plus1 before the upgrade which seems to show only 1 critical CVE in the ECR scan which has gone up to 43 on the latest 41.3.3-plus1 - which is now reduced to 32 after applying OS patches.
Details
Total: 9 unique CVEs → 32 ECR scanner rows:
Impact
Have gone through https://github.com/sitespeedio/sitespeed.io/security/policy before raising this.
Can you please confirm if these CVEs listed above are not exploitable in sitespeed.io's threat model.
Will be helpful to have this assessment and advice on next steps on this from your side. Thank you.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the sitespeed.io security policy, the 41.3.3-plus1 Docker image, and the AWS ECR scan details in the issue. Verify the reported ImageMagick and cJSON CVEs against the Ubuntu Noble package versions and assess them against the project's threat model. Done means documenting whether they are exploitable and advising on next steps.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, docker, ubuntu
- Domain
- devops, infrastructure, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100