Uploaded image for project: 'Guacamole'
  1. Guacamole
  2. GUACAMOLE-1768

Docker - Guacamole Vulnerability Updates

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Invalid
    • 1.5.0
    • None
    • guacamole, guacd-docker
    • None

    Description

      Hi,

       

      I was doing a synk vulnerability scan with "docker scan" to see what vulnerabilities were in the docker image. I saw the below, and was inquiring how the docker components get updated from a vulnerability perspective?

       

      Issues to fix by upgrading:

        Upgrade com.fasterxml.woodstox:woodstox-core@5.2.1 to com.fasterxml.woodstox:woodstox-core@5.4.0 to fix
        ✗ Denial of Service (DoS) [Medium Severity]https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLWOODSTOX-3091135 in com.fasterxml.woodstox:woodstox-core@5.2.1
          introduced by com.fasterxml.woodstox:woodstox-core@5.2.1
        ✗ XML External Entity (XXE) Injection [Critical Severity]https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLWOODSTOX-2928754 in com.fasterxml.woodstox:woodstox-core@5.2.1
          introduced by com.fasterxml.woodstox:woodstox-core@5.2.1

       

      The above is from the latest guacamole docker image. For guacd, there wasn't anything shown at the moment.

       

       

      Attachments

        Activity

          People

            Unassigned Unassigned
            kintaroju Jonathan Kwan
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: