upvote
These are CVEs in the base image and in standard lib dependencies. For example, just scanned an unhardened image I built today:

  Unhardened: docker.io/nanoco/nanoclaw:agent-alpha
  71 packages, 344 unique CVEs, linux/arm64

  PACKAGE         VERSION        TYP   C   H   M   L   N  TOT
  -----------------------------------------------------------
  expat           2.5.0          deb   0   4  18   1   2   25
  curl            7.88.1         deb   4   4   6   0   7   21
  hono            4.12.14        npm   0   1  18   2   0   21
  libtiff         4.5.0          deb   0   2   1   1  15   20
  perl            5.36.0         deb   5   6   3   0   3   17
  pnpm            10.33.0        npm   0   8   7   0   0   15
  glibc           2.36           deb   1   2   2   1   7   13
  openjpeg        2.5.0          deb   0   0   3   1   9   13
  cups            2.4.2          deb   0   2   8   0   1   11
  glib2           2.74.6         deb   1   7   1   0   1   10
  tar             1.34(+2)       deb   1   1   7   0   1   10
  llvm            15.0.6         deb   0   0   0   1   9   10
  sqlite3         3.40.1         deb   1   2   3   0   3    9
  nss             3.87.1         deb   1   0   3   0   4    8
  avahi           0.8            deb   0   0   8   0   0    8
  util-linux      2.38.1         deb   0   0   3   0   2    7
  elf             0.188          deb   0   0   0   0   7    7
  libssh2         1.10.0         deb   1   4   1   0   0    6
  openldap        2.5.13         deb   0   1   0   0   5    6
  chromium        151.0.7922.108 deb   0   5   0   0   0    5
  -----------------------------------------------------------
  UNIQUE CVEs                         16  68 121  17 119  344

  (+51 more packages, 102 findings)

  C/H/M/L/N = critical/high/medium/low/negligible.
  Counts are unique CVEs: binaries from one source package are
  grouped (libcurl4 + libcurl3-gnutls + curl = curl), so a CVE
  hitting three of them counts once, not three times.
reply
deleted
reply
Are these real findings, or a situation in which fixes have been backported? At one place I worked, the corpsec guys were wildly incompetent and would try to bury me in "CVEs" in my systems that were nothing but "vulnerable" software versions with all of the "identified" vulnerabilities fixed by Debian backported patches.
reply
Most modern scanners know the backported versions for the major vendors (ubuntu/debian/rhel/alpine), but it was definitely an issue a decade ago.
reply
That’s not security, it’s compliance.
reply
deleted
reply
If the thing measuring whether there are CVEs is also the thing creating said CVEs, are we sure they are even CVEs? Deduped? Etc.
reply
deleted
reply
deleted
reply
Hold my beer
reply
It’s like it’s made of CVEs. First 50-100 should be a good sign if it’s cleaner to start over.
reply