I just uploaded images based on various Lucee imag...
# lucee
a
I just uploaded images based on various Lucee images from Docker Hub to our repo, where we have snyk scans running automatically. Results:

https://i2.paste.pics/f08e330be91f100167fd18306e70f89c.png▾

z
5.4.0.66 fixes the hsqldb problem
a
Contrast this with our latest PHP image we use (8.2.5):

https://i2.paste.pics/fdec1a36562a785b2721b6a372af837e.png▾

z
hibernate is being worked on
@justincarter @Mark Drew (he/him) we need to update the docker images used?
a
I dunno if we can run the light version of Lucee... that's certainly better. (We're currently stuck on 5.3.9.166 anyhow, unfortunately) My InfoSec person is willing to overlook the non-critical ones. But they're baulking at the number of criticals.
NB: just an observation, not a hurry up. We know where we are with this stuff. Just figured you should know what ppl will be seeing when they scan your images.
m
What are the main issues? Log4J?
a
This stuff is way beyond my abilities (or time to improve same) to deal with meself.
(sorry)
m
Will go have a look
z
nah the linux images mostly
m
Where is this? Do you have a link?
z
that's a report in docker desktop
https://github.com/lucee/lucee-dockerfiles/actions/workflows/main.yml wip branch (5.4 and 6.0 don't build auto yet)
a
It's the report snyk gives us on Docker Hub. It's not a public repo, sorry
z
image.png
the bundled lucee jars are being addressed by @micha
m
Aha, I will push something and see if I can see the details
a
These are the details of the criticals, extracted from our report:
Copy code
Severity & Vulnerability	Package	Version	Fixed in
C 10 Server-Side Request Forgery (SSRF) CVE-2018-14721	jackson-databind	2.9.6	2.9.7
C 9.8 Integer Overflow or Wraparound CVE-2022-41903	git	1:2.30.2-1	1:2.30.2-1+deb11u1
C 9.8 Deserialization of Untrusted Data CVE-2019-14892	jackson-databind	2.9.6	2.9.10
C 9.8 Integer Overflow or Wraparound CVE-2022-3515	libksba	1.5.0-3	1.5.0-3+deb11u1
C 9.8 Deserialization of Untrusted Data CVE-2019-16942	jackson-databind	2.9.6	2.9.10.1
C 9.8 Integer Overflow or Wraparound CVE-2022-23521	git	1:2.30.2-1	1:2.30.2-1+deb11u1
C 9.8 Deserialization of Untrusted Data CVE-2018-14720	jackson-databind	2.9.6	2.9.7
C 9.8 Deserialization of Untrusted Data CVE-2018-19361	jackson-databind	2.9.6	2.9.8
C 9.8 Deserialization of Untrusted Data CVE-2020-9548	jackson-databind	2.9.6	2.9.10.4
C 9.8 Exposure of Sensitive Information to an Unauthorized Actor CVE-2022-32221	curl	7.74.0-1.3+deb11u2	7.74.0-1.3+deb11u5
C 9.8 Deserialization of Untrusted Data CVE-2019-17267	jackson-databind	2.9.6	2.9.10
C 9.8 Deserialization of Untrusted Data CVE-2019-14893	jackson-databind	2.9.6	2.9.10
C 9.8 Deserialization of Untrusted Data CVE-2019-20330	jackson-databind	2.9.6	2.9.10.2
C 9.8 Deserialization of Untrusted Data CVE-2018-19362	jackson-databind	2.9.6	2.9.8
C 9.8 Deserialization of Untrusted Data CVE-2020-8840	jackson-databind	2.9.6	2.9.10.3
C 9.8 Out-of-bounds Write CVE-2022-37434	zlib	1:1.2.11.dfsg-2+deb11u1	1:1.2.11.dfsg-2+deb11u2
C 9.8 Deserialization of Untrusted Data CVE-2019-14540	jackson-databind	2.9.6	2.9.10
C 9.8 Deserialization of Untrusted Data CVE-2019-17531	jackson-databind	2.9.6	2.9.10.1
C 9.8 Deserialization of Untrusted Data CVE-2020-9546	jackson-databind	2.9.6	2.9.10.4
C 9.8 Deserialization of Untrusted Data CVE-2020-9547	jackson-databind	2.9.6	2.9.10.4
C 9.8 Deserialization of Untrusted Data CVE-2018-14719	jackson-databind	2.9.6	2.9.7
C 9.8 Deserialization of Untrusted Data CVE-2018-19360	jackson-databind	2.9.6	2.9.8
C 9.8 Deserialization of Untrusted Data CVE-2015-7501	commons-collections	3.2.1	3.2.2
C 9.8 Integer Overflow or Wraparound CVE-2022-47629	libksba	1.5.0-3	1.5.0-3+deb11u2
C 9.8 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') CVE-2019-14379	jackson-databind	2.9.6	2.9.9.2
C 9.8 Deserialization of Untrusted Data CVE-2019-16943	jackson-databind	2.9.6	2.9.10.1
C 9.8 Deserialization of Untrusted Data CVE-2018-14718	jackson-databind	2.9.6	2.9.7
C 9.8 Deserialization of Untrusted Data CVE-2019-16335	jackson-databind	2.9.6	2.9.10
C 9.1 Out-of-bounds Read CVE-2022-1586	pcre2	10.36-2	10.36-2+deb11u1
C 9.1 Out-of-bounds Read CVE-2022-1587	pcre2	10.36-2	10.36-2+deb11u1
All claim to have fixes, as you can see. Main culprit is that jackson thing... same on Zac~k~'s report.
z
no horse tranquliser plz, i mean no k 😉
😜 1