-
Notifications
You must be signed in to change notification settings - Fork 2.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
docker image gitlab-ce:17.6.0-ce.0,OpenSSH_8.9p1 version is too low and has high-risk vulnerabilities #3037
Comments
This is a repository for |
Also note that it is difficult to determine whether there is a vulnerability just by the version number (here, Full version string of openssh-server package for ubuntu is "8.9p1-3ubuntu0.10" etc. It can be checked by executing The version
By the way, I think it's better to upgrade base image to ubuntu:jammy which provides |
I see. Thanks for the reminder. |
You can close this issue if you don't need this. |
I went to https://launchpad.net/ubuntu/+source/openssh and found that version 8.9p1-3ubuntu0.10 did fix the vulnerability CVE-2024-6387, and another vulnerability CVE-2024-39894 in the later version only affects OpenSSH versions between 9.5 and 9.8. Therefore, it seems that this version 8.9p1-3ubuntu0.10 is safe. |
docker image:
or
The latest version of OpenSSH is OpenSSH_9.8p1, please upgrade to the latest version.
The text was updated successfully, but these errors were encountered: