Skip to content

Image vulnerability in postgres:latest #995

Closed
@bharath3745

Description

@bharath3745

Hi Team,

We are using the latest Postgres image in our environment in both dev and prod environments. We are seeing the following vulnerability popped up in our environment for this image.

summary:
Nick Wellnhofer discovered that the xsltApplyTemplates function in libxslt, an XSLT processing runtime library, is prone to a use-after-free flaw, resulting in a denial of service, or potentially the execution of arbitrary code if a specially crafted file is processed.

Issue:
postgres:latest-CVE-2021-30560
libxslt1.1 has vulnerabilities

Action:
Upgrade libxslt1.1 to >= 1.1.34-4+deb11u1

Request you to kindly update the libxslt to the latest version and push the new image.

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionUsability question, not directly related to an error with the image

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions