Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE found in Busybox 1.34.1 and 1.35.0 #61

Open
vvviren opened this issue Sep 28, 2022 · 8 comments
Open

CVE found in Busybox 1.34.1 and 1.35.0 #61

vvviren opened this issue Sep 28, 2022 · 8 comments

Comments

@vvviren
Copy link

vvviren commented Sep 28, 2022

Both Busybox 1.34.1 and 1.35.0 are affected by Critical CVE https://nvd.nist.gov/vuln/detail/cve-2022-28391

Can you please provide any update on when is this going to be fixed with the expected version number.

Thank you

@addisonautomates
Copy link

addisonautomates commented Nov 22, 2022

Bumping this. Would like to know if this is on the roadmap. We currently use alpine as our gold image of source which has dependency on busybox 1.35.0 and we have 2 critical CVEs due to this version. Will likely have to abandon alpine and refactor a lot of our apps unless this will be remediated

@uGiFarukh
Copy link

Is the busybox project dead? Why no updates for almost 2 years?

@robang74
Copy link
Contributor

robang74 commented Jan 2, 2023 via email

@wdlkmpx
Copy link

wdlkmpx commented Jan 2, 2023

Yeah it's dead

@fxzxmic
Copy link

fxzxmic commented Jan 5, 2023

Is the busybox project dead? Why no updates for almost 2 years?

A new version was released a few days ago. How did you come to the conclusion that it was dead?

@vvviren
Copy link
Author

vvviren commented Jan 24, 2023

Is the issue resolved in busybox 1.35.0 ? I don’t see info on this CVE in the changelog.

@fxzxmic
Copy link

fxzxmic commented Jan 26, 2023

Is the issue resolved in busybox 1.35.0 ? I don’t see info on this CVE in the changelog.

It should be fixed in version 1.36.0.

@fxzxmic
Copy link

fxzxmic commented Jan 26, 2023

This is just a mirror repository. Developers may not pay attention to the issue here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants