Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix critical CVE in cmd-dashboard-ui #12493

Open
Ex4amp1e opened this issue Oct 23, 2024 · 0 comments
Open

Fix critical CVE in cmd-dashboard-ui #12493

Ex4amp1e opened this issue Oct 23, 2024 · 0 comments

Comments

@Ex4amp1e
Copy link
Contributor

Expected Behavior

No CVE scanner errors

Current Behavior

https://github.com/networkservicemesh/deployments-k8s/security/code-scanning/40331

Failure Information (for bugs)

ghcr.io/networkservicemesh/ci/cmd-dashboard-ui:14da2e1
Vulnerability : CVE-2024-24790
Severity : CRITICAL
Package : pkg:golang/[email protected]
Affected range : <1.21.11
Fixed version : 1.21.11
EPSS Score : 0.000630
EPSS Percentile : 0.279490

Note: uplifting of the all dependencies has not resolved a problem, npm audit fix doesn't help, snyk scanner also can't find any problems after uplifting all dependencies to the latest version. Anyway the CVE error exists in the docker image, it comes not from base image, but from "npm install" dockerfile step, so some dependency contains vulnerable version of the go lib.

Expected to wait updates from package.json dependencies to resolve the issue, since current latest versions do not resolve the issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant