Title: Vulnerable base Amazon image · Issue #33 · rust-serverless/lambda-rust · GitHub
Open Graph Title: Vulnerable base Amazon image · Issue #33 · rust-serverless/lambda-rust
X Title: Vulnerable base Amazon image · Issue #33 · rust-serverless/lambda-rust
Description: According to the CI, our base Amazon image has security issues: https://github.com/rust-serverless/lambda-rust/runs/4399791210?check_suite_focus=true +--------------------+------------------+----------+-------------------+---------------...
Open Graph Description: According to the CI, our base Amazon image has security issues: https://github.com/rust-serverless/lambda-rust/runs/4399791210?check_suite_focus=true +--------------------+------------------+------...
X Description: According to the CI, our base Amazon image has security issues: https://github.com/rust-serverless/lambda-rust/runs/4399791210?check_suite_focus=true +--------------------+------------------+------...
Opengraph URL: https://github.com/rust-serverless/lambda-rust/issues/33
X: @github
Domain: patch-diff.githubusercontent.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Vulnerable base Amazon image","articleBody":"According to the CI, our base Amazon image has security issues: https://github.com/rust-serverless/lambda-rust/runs/4399791210?check_suite_focus=true\r\n\r\n```\r\n+--------------------+------------------+----------+-------------------+--------------------+---------------------------------------+\r\n| LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE |\r\n+--------------------+------------------+----------+-------------------+--------------------+---------------------------------------+\r\n| nspr | CVE-2021-43527 | CRITICAL | 4.25.0-2.amzn2 | 4.32.0-1.amzn2 | nss: Memory corruption in |\r\n| | | | | | decodeECorDsaSignature with |\r\n| | | | | | DSA signatures (and RSA-PSS) |\r\n| | | | | | --\u003eavd.aquasec.com/nvd/cve-2021-43527 |\r\n+--------------------+ + +-------------------+--------------------+ +\r\n| nss | | | 3.53.1-7.amzn2 | 3.67.0-4.amzn2.0.1 | |\r\n| | | | | | |\r\n| | | | | | |\r\n| | | | | | |\r\n+--------------------+ + +-------------------+--------------------+ +\r\n| nss-softokn | | | 3.53.1-6.amzn2 | 3.67.0-3.amzn2 | |\r\n| | | | | | |\r\n| | | | | | |\r\n| | | | | | |\r\n+--------------------+ + + + + +\r\n| nss-softokn-freebl | | | | | |\r\n| | | | | | |\r\n| | | | | | |\r\n| | | | | | |\r\n+--------------------+ + +-------------------+--------------------+ +\r\n| nss-sysinit | | | 3.53.1-7.amzn2 | 3.67.0-4.amzn2.0.1 | |\r\n| | | | | | |\r\n| | | | | | |\r\n| | | | | | |\r\n+--------------------+ + + + + +\r\n| nss-tools | | | | | |\r\n| | | | | | |\r\n| | | | | | |\r\n| | | | | | |\r\n+--------------------+ + +-------------------+--------------------+ +\r\n| nss-util | | | 3.53.1-1.amzn2 | 3.67.0-1.amzn2 | |\r\n| | | | | | |\r\n| | | | | | |\r\n| | | | | | |\r\n+--------------------+------------------+----------+-------------------+--------------------+---------------------------------------+\r\n```\r\n\r\nWe need somehow fix it. Maybe, we need just wait for the fix from AWS side and possibly bump our base image version. Also, we can somehow highlight the issue to the AWS related people.","author":{"url":"https://github.com/zamazan4ik","@type":"Person","name":"zamazan4ik"},"datePublished":"2021-12-02T20:12:17.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":2},"url":"https://github.com/33/lambda-rust/issues/33"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:56ecf752-82a0-d4be-ce85-0e6ccfe0edc8 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | DA4A:BFBA6:8A75D7:B2E6D0:699053B2 |
| html-safe-nonce | 7b3b4eece75849f7976e5ae40d359797a871a553429800b0e0ec7b18c4ecd857 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJEQTRBOkJGQkE2OjhBNzVENzpCMkU2RDA6Njk5MDUzQjIiLCJ2aXNpdG9yX2lkIjoiODQzMjY5NzkxODU4ODQwNDk4IiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | 9c1607496b157593683f4bdf5f84ba8d7bcd0dc8f1008f25a703235d8dafa9dc |
| hovercard-subject-tag | issue:1069941446 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/rust-serverless/lambda-rust/33/issue_layout |
| twitter:image | https://opengraph.githubassets.com/d58649dc7e89da1a9a236d648c4bb6be750e6f8c724e56534a852d17cc21e805/rust-serverless/lambda-rust/issues/33 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/d58649dc7e89da1a9a236d648c4bb6be750e6f8c724e56534a852d17cc21e805/rust-serverless/lambda-rust/issues/33 |
| og:image:alt | According to the CI, our base Amazon image has security issues: https://github.com/rust-serverless/lambda-rust/runs/4399791210?check_suite_focus=true +--------------------+------------------+------... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | zamazan4ik |
| hostname | github.com |
| expected-hostname | github.com |
| None | 42c603b9d642c4a9065a51770f75e5e27132fef0e858607f5c9cb7e422831a7b |
| turbo-cache-control | no-preview |
| go-import | github.com/rust-serverless/lambda-rust git https://github.com/rust-serverless/lambda-rust.git |
| octolytics-dimension-user_id | 88410118 |
| octolytics-dimension-user_login | rust-serverless |
| octolytics-dimension-repository_id | 392490725 |
| octolytics-dimension-repository_nwo | rust-serverless/lambda-rust |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | true |
| octolytics-dimension-repository_parent_id | 160704679 |
| octolytics-dimension-repository_parent_nwo | softprops/lambda-rust |
| octolytics-dimension-repository_network_root_id | 160704679 |
| octolytics-dimension-repository_network_root_nwo | softprops/lambda-rust |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 3b33c5aedc9808f45bc5fcf0b1e4404cf749dac7 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width