Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fluent-bit critical vulnerabilty not detected #6794

Closed
1 of 2 tasks
pradyumnaparalikar opened this issue May 27, 2024 Discussed in #6793 · 1 comment
Closed
1 of 2 tasks

fluent-bit critical vulnerabilty not detected #6794

pradyumnaparalikar opened this issue May 27, 2024 Discussed in #6793 · 1 comment

Comments

@pradyumnaparalikar
Copy link

Discussed in #6793

Originally posted by pradyumnaparalikar May 27, 2024

IDs

CVE-2024-4323

Description

fluent-bit component for log processing. There was CRITICAL 9.8 CVE discovered in the application recently - https://fluentbit.io/blog/2024/05/21/statement-on-cve-2024-4323-and-its-fix/

The problem is that trivy isn’t detecting fluent-bit being installed in the container image and thus not reporting the issue. This problem can be easily replicated by running trivy scanner locally:

Reproduction Steps

trivy i cr.fluentbit.io/fluent/fluent-bit:2.1.4 -s CRITICAL

Target

Container Image

Scanner

Vulnerability

Target OS

No response

Debug Output

trivy i cr.fluentbit.io/fluent/fluent-bit:2.1.4 -s CRITICAL

Version

Version:v0.44.0

Checklist

Copy link

@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale May 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant