Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical/High Severity issues reported by Snyk for neo4j:5.18.1 #490

Open
IanT111 opened this issue Mar 25, 2024 · 0 comments
Open

Critical/High Severity issues reported by Snyk for neo4j:5.18.1 #490

IanT111 opened this issue Mar 25, 2024 · 0 comments
Assignees

Comments

@IanT111
Copy link

IanT111 commented Mar 25, 2024

Description

When performing a snyk IAC scan against the container image we are receiving 1 Critical and 1 High severity issues in v5.18.1

Steps to reproduce

snyk container test neo4j:5.18.1 --severity-threshold=high

Expected behaviour

No high or critical vulnerabilities found

Actual behaviour

1 Critical and 1 High severity vulnerabilities found

Testing neo4j:5.18.1...

✗ High severity vulnerability found in systemd/libsystemd0
  Description: Allocation of Resources Without Limits or Throttling
  Info: https://security.snyk.io/vuln/SNYK-DEBIAN11-SYSTEMD-6277510
  Introduced through: [email protected], util-linux/bsdutils@1:2.36.1-8+deb11u1, util-linux/[email protected]+deb11u1, procps@2:3.3.[17](https://github.com/SSEPLC/cceo-prod-private-container-image/actions/runs/8420409320/job/23055058492#step:6:18)-5, systemd/[email protected]+deb11u4
  From: [email protected] > systemd/[email protected]+deb11u4
  From: util-linux/bsdutils@1:2.36.1-8+deb11u1 > systemd/[email protected]+deb11u4
  From: [email protected] > apt/[email protected] > systemd/[email protected]+deb11u4
  and 5 more...
  Image layer: 'apt-get install -y curl gcc git jq make procps tini wget'

✗ Critical severity vulnerability found in zlib/zlib1g
  Description: Integer Overflow or Wraparound
  Info: https://security.snyk.io/vuln/SNYK-DEBIAN11-ZLIB-6008961
  Introduced through: zlib/zlib1g@1:1.2.11.dfsg-2+deb11u2
  From: zlib/zlib1g@1:1.2.11.dfsg-2+deb11u2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants