<#106 Vulnerability issues with pact-broker-docker...
# pact-broker
g
#106 Vulnerability issues with pact-broker-docker:latest and 2.106.0.1 Issue created by nick130589 Pre issue-raising checklist I have already (please mark the applicable with an
x
): ☑︎ Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project. ☑︎ Upgraded to the latest Pact Broker Docker image OR ☑︎ Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed ☑︎ Read the Troubleshooting page Software versions • pact-broker gem version: 2.106.0.1 • pact-broker docker version: 2.106.0.1 Expected behaviour The image doesn't contain critical, high and medium vulnerabilities Actual behaviour The following non-operating system vulnerabilities were found: Critical: CVE-2022-37434 - Package zlib 1.1.0 - /usr/local/lib/ruby/gems/2.7.0/specifications/default/zlib-1.1.0.gemspec High: CVE-2018-25032 - Package zlib 1.1.0 - /usr/local/lib/ruby/gems/2.7.0/specifications/default/zlib-1.1.0.gemspec High: CVE-2020-36327 - Package bundler 2.1.4 - /usr/local/lib/ruby/gems/2.7.0/specifications/default/bundler-2.1.4.gemspec High: CVE-2021-43809 - Package bundler 2.1.4 - /usr/local/lib/ruby/gems/2.7.0/specifications/default/bundler-2.1.4.gemspec Medium: VULNDB-219586 - Package psych 3.1.0 - Fix: psych 3.2.0 Steps to reproduce Perform scan docker image by https://sysdig.com/ scanner Relevent log files N/A pact-foundation/pact-broker-docker