slimtoolkit / slimtoolkit/slim
CVE-2024-45337: Trivy reports Critical vulnerability in current version of mint
Open
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 23.4k
- Forks
- 840
- PR merge metrics
- No merged PRs in 30d
Description
I ran “trivy image --severity=CRITICAL --no-progress --exit-code 1 $(IMAGE)” on an image where I’d installed docker-slim (SLIM_VERSION=1.40.11). It triggered this failure.
usr/local/bin/mint (gobinary)
Total: 1 (CRITICAL: 1)
┌─────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├─────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────┤
│ golang.org/x/crypto │ CVE-2024-45337 │ CRITICAL │ fixed │ v0.29.0 │ 0.31.0 │ golang.org/x/crypto/ssh: Misuse of │
│ │ │ │ │ │ │ ServerConfig.PublicKeyCallback may cause authorization │
│ │ │ │ │ │ │ bypass in golang.org/x/crypto │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2024-45337 │
└─────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴────────────────────────────────────────────────────────┘
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the reported trivy image --severity=CRITICAL --no-progress --exit-code 1 $(IMAGE) scan against an image containing /usr/local/bin/mint from docker-slim 1.40.11. Trace the Go dependency or build configuration that supplies golang.org/x/crypto v0.29.0, update it to a version containing the CVE-2024-45337 fix, and confirm Trivy no longer reports the critical vulnerability.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, go
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100