sitespeedio / sitespeedio/sitespeed.io

32 Critical CVEs in 41.3.3-plus1 sitespeedio Docker image - detected in the AWS ECR scans

Open
#4,796 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
5k
Forks
624
Avg merge
4h 8m
Merged PRs (30d)
2

Description

Your question
Summary

We recently upgraded to 41.3.3 version and used sitespeedio/sitespeed.io 41.3.3-plus1 docker image for the same. As per my understanding the sitespeedio is built on Ubuntu 24.04 LTS (Noble) and the Ubuntu Noble package repository currently ships imagemagick 6.9.12.98+dfsg1-5.2build2, which is affected by 8 critical ImageMagick CVEs and 1 critical cJSON CVE - totalling 32 critical vulnerability rows in AWS ECR enhanced scanning.

We have applied a downstream OS patching layer (apt-get update && apt-get upgrade -y) on top of the upstream image which reduced the CVEs from 43 to 32, but this has no effect on the ImageMagick CVEs may be because Ubuntu Noble has not yet published the patched package in its security repository.

Please note: We were on sitespeedio version 37.4.1-plus1 before the upgrade which seems to show only 1 critical CVE in the ECR scan which has gone up to 43 on the latest 41.3.3-plus1 - which is now reduced to 32 after applying OS patches.

Details

Total: 9 unique CVEs → 32 ECR scanner rows:
Image

Image
Impact

Have gone through https://github.com/sitespeedio/sitespeed.io/security/policy before raising this.
Can you please confirm if these CVEs listed above are not exploitable in sitespeed.io's threat model.
Will be helpful to have this assessment and advice on next steps on this from your side. Thank you.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the sitespeed.io security policy, the 41.3.3-plus1 Docker image, and the AWS ECR scan details in the issue. Verify the reported ImageMagick and cJSON CVEs against the Ubuntu Noble package versions and assess them against the project's threat model. Done means documenting whether they are exploitable and advising on next steps.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, docker, ubuntu
Domain
devops, infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.