Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

composer:latest 2.4.4 CVE-2022-37454 #270

Open
IshtarStar opened this issue Dec 13, 2022 · 0 comments
Open

composer:latest 2.4.4 CVE-2022-37454 #270

IshtarStar opened this issue Dec 13, 2022 · 0 comments

Comments

@IshtarStar
Copy link

IshtarStar commented Dec 13, 2022

Today I have a blocker of my pipelines with the following vulnerability.
https://avd.aquasec.com/nvd/2022/cve-2022-37454/

#8 [internal] load metadata for DOMAIN/composer:latest
#8 ERROR: failed to copy: httpReadSeeker: failed open: unexpected status code DOMAIN/composer/manifests/sha256:09d472357d154632b613bfd2ed997a52fbf343f123c23e17537b47f85049b36d: 412 Precondition Failed - Server message: unknown: current image with 3 vulnerabilities cannot be pulled due to configured policy in 'Prevent images with vulnerability severity of "Critical" or higher from running.' To continue with pull, please contact your project administrator to exempt matched vulnerabilities through configuring the CVE allowlist.

 > [internal] load metadata for DOMAIN/composer:latest:

failed to solve: rpc error: code = Unknown desc = failed to solve with frontend dockerfile.v0: failed to create LLB definition: failed to copy: httpReadSeeker: failed open: unexpected status code DOMAIN/composer/manifests/sha256:09d472357d154632b613bfd2ed997a52fbf343f123c23e17537b47f85049b36d: 412 Precondition Failed - Server message: unknown: current image with 3 vulnerabilities cannot be pulled due to configured policy in 'Prevent images with vulnerability severity of "Critical" or higher from running.' To continue with pull, please contact your project administrator to exempt matched vulnerabilities through configuring the CVE allowlist.

The scanner trivy sounds an alarm about Python3 inside it.
He gets off with us with the following errors. Is there perhaps a solution for this in a timely manner?

Thanks

@IshtarStar IshtarStar changed the title CVE-2022-37454 -> 9.8 CRITICAL composer:latest 2.4.4 CVE-2022-37454 -> 9.8 CRITICAL Dec 13, 2022
@IshtarStar IshtarStar changed the title composer:latest 2.4.4 CVE-2022-37454 -> 9.8 CRITICAL composer:latest 2.4.4 CVE-2022-37454 Dec 13, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant