Skip to content
This repository has been archived by the owner on Oct 28, 2023. It is now read-only.

arkserver docker image has sudo security issue CVE2021-3156 - please provide new image #32

Open
maecki-maecki opened this issue Jan 29, 2021 · 6 comments
Labels
security Security related issue

Comments

@maecki-maecki
Copy link

maecki-maecki commented Jan 29, 2021

Description of Issue

CVE-2021-3156 means sudo is exploitable - this is fixed in xenial, but arkserver/steamcmd image has to be rebuild/republished for fix to be included ...

https://ubuntu.com/security/CVE-2021-3156

@jkread
Copy link

jkread commented Feb 11, 2021

I haven't gotten any luck getting response to anything for a while. I forked and have fixed a few of the outstanding issues.

https://github.com/jkread/arkserver

@stale
Copy link

stale bot commented Mar 15, 2021

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the stale label Mar 15, 2021
@stale stale bot closed this as completed Mar 19, 2021
@thmhoag
Copy link
Owner

thmhoag commented Mar 19, 2021

Sorry for the delay here @maecki-maecki. Do you have a link to the description of that CVE for posterity? Happy to re-open and address the issue but I wasn't able to find any specifics when I searched for that CVE number.

@thmhoag thmhoag added the security Security related issue label Mar 19, 2021
@maecki-maecki
Copy link
Author

maecki-maecki commented Mar 19, 2021 via email

@thmhoag thmhoag removed the stale label Mar 19, 2021
@thmhoag
Copy link
Owner

thmhoag commented Mar 19, 2021

Thanks @maecki-maecki, all good. I'm re-opening this, should be a pretty straight-forward fix with an update to the base image.

Linking the base image for posterity: https://github.com/thmhoag/steamcmd

@thmhoag thmhoag reopened this Mar 19, 2021
@Gornoka
Copy link

Gornoka commented Oct 7, 2023

I updated the base image and build pipeline on my fork, if this is still relevant to you @maecki-maecki .
https://github.com/Gornoka/arkserver

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
security Security related issue
Projects
None yet
Development

No branches or pull requests

4 participants