GitHub
02/09/2023, 5:52 PMx):
☑︎ Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project.
☑︎ Upgraded to the latest Pact Broker Docker image OR
☑︎ Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed
☑︎ Read the Troubleshooting page
Software versions
• pact-broker gem version: 2.106.0.1
• pact-broker docker version: 2.106.0.1
Expected behaviour
The image doesn't contain critical, high and medium vulnerabilities
Actual behaviour
The following non-operating system vulnerabilities were found:
Critical: CVE-2022-37434 - Package zlib 1.1.0 - /usr/local/lib/ruby/gems/2.7.0/specifications/default/zlib-1.1.0.gemspec
High: CVE-2018-25032 - Package zlib 1.1.0 - /usr/local/lib/ruby/gems/2.7.0/specifications/default/zlib-1.1.0.gemspec
High: CVE-2020-36327 - Package bundler 2.1.4 - /usr/local/lib/ruby/gems/2.7.0/specifications/default/bundler-2.1.4.gemspec
High: CVE-2021-43809 - Package bundler 2.1.4 - /usr/local/lib/ruby/gems/2.7.0/specifications/default/bundler-2.1.4.gemspec
Medium: VULNDB-219586 - Package psych 3.1.0 - Fix: psych 3.2.0
Steps to reproduce
Perform scan docker image by https://sysdig.com/ scanner
Relevent log files
N/A
pact-foundation/pact-broker-docker