-
Notifications
You must be signed in to change notification settings - Fork 57
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
RStudio Workbench CVEs #681
Comments
@securian-bpmcd Thank you for reporting these! Do you still see these vulnerabilities in the latest image?
|
@bschwedler We're using RStudio on SageMaker and the most recent version that we can use to match the AWS environment is 2024.04.2 |
The 2024.04.2 image scan reports the following CVEs: |
Ah, thanks for the added detail on where you are seeing this. I also want to add a little more detail around patching and rebuilding previous versions of the container images. We are currently routinely rebuilding the most recent version of the container images to pick up OS and package security updates. The current repository structure makes it difficult to use the same rebuild process for previous container versions. We are working to improve the workflows as well as the visibility of our internal scan results. |
The below CVEs affect Go 1.19. These were found by our Prisma Cloud Scan tool while scanning the current (12/27/2023) "rstudio/r-session-complete:jammy-2023.03.2" image.
CVE-2023-39323 Go
CVE-2023-29405 Go
CVE-2023-29404 Go
CVE-2023-29402 Go
CVE-2023-24540 Go
CVE-2023-24538 Go
The text was updated successfully, but these errors were encountered: