Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

250+ CVEs In Red Hat Linux Splunk Docker Image #616

Open
Subrhamanya opened this issue Aug 2, 2023 · 10 comments
Open

250+ CVEs In Red Hat Linux Splunk Docker Image #616

Subrhamanya opened this issue Aug 2, 2023 · 10 comments
Assignees

Comments

@Subrhamanya
Copy link

Subrhamanya commented Aug 2, 2023

Recently splunk official image scanned with one of our scanners (Prisma Cloud) and it's showing 250+ CVEs in it.

image

We are using splunk docker from https://hub.docker.com/r/splunk/splunk/tags?page=1

Is this image legitimate and offcial?

Can anybody help with it? So many CVEs in one image is confusing us...

@aakarshsingh
Copy link

Critical: 20
High: 93
Medium: 60
Low: 108

Total: 281

@yaroslav-nakonechnikov
Copy link

yaroslav-nakonechnikov commented Aug 18, 2023

jyst fyi: splunk support case: 3276273 with results from ORCA

ps. fixing base image may also fix problem with journald, which was also reported in 3270730

@yaroslav-nakonechnikov
Copy link

#576

@yaroslav-nakonechnikov
Copy link

#518

@yaroslav-nakonechnikov
Copy link

#602

@yaroslav-nakonechnikov
Copy link

#589

@jmeixensperger
Copy link
Contributor

We have started daily scanning for these images internally on the latest/upcoming splunk versions, and we are focusing on efforts to resolve all critical/high level vulnerabilities. Unfortunately, most of these are coming from the Splunk product itself and not from the docker image layers that we build. We have resolved all critical and most high level vulnerabilities that are not coming from the Splunk build for the upcoming release.

@Subrhamanya
Copy link
Author

@jmeixensperger thanks for looking into it.

@yaroslav-nakonechnikov
Copy link

@Subrhamanya can you attach last scan results for "fresh" versions?

@Subrhamanya
Copy link
Author

Subrhamanya commented Oct 17, 2024

@yaroslav-nakonechnikov here is the screenshot. Version scanned --> 9.3.1

image

Critical - 1
High - 10
Medium - 47
Low - 149

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants