quay / clair

Vulnerability Static Analysis for Containers

Home Page:https://quay.github.io/clair/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Clair v2.1.7 official image has vulnerabilities

vmicrodev opened this issue · comments

commented

Description of Problem / Feature Request

Scan image quay.io/coreos/clair:v2.1.7 with klar binary klar-2.4.0-linux-amd64 and clair v2.1.7
Analysing 8 layers
Got results from Clair API v1
Found 4 vulnerabilities
Low: 1
Medium: 3

Expected Outcome

Found 0 vulnerabilities

Actual Outcome

Scan image quay.io/coreos/clair:v2.1.7 with klar binary klar-2.4.0-linux-amd64 and clair v2.1.7
Analysing 8 layers
Got results from Clair API v1
Found 4 vulnerabilities
Low: 1
Medium: 3

CVE-2020-28928: [Low]
Found in: musl [1.1.24-r9]
Fixed By: 1.1.24-r10

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28928

CVE-2021-28831: [Medium]
Found in: busybox [1.31.1-r16]
Fixed By: 1.31.1-r20

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28831

CVE-2021-36159: [Medium]
Found in: apk-tools [2.10.5-r1]
Fixed By: 2.10.7-r0

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36159

CVE-2021-30139: [Medium]
Found in: apk-tools [2.10.5-r1]
Fixed By: 2.10.6-r0

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30139

Environment

Clair version/image: V2.1.7
Clair client name/version:
Host OS: Debian GNU/Linux 10 (buster)
Kernel (e.g. uname -a): Linux ip-10-110-42-59 4.19.0-17-cloud-amd64 Docs: fix some typos in README.md #1 SMP Debian 4.19.194-3 (2021-07-18) x86_64 GNU/Linux
Kubernetes version (use kubectl version):
Network/Firewall setup: