Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixing Vulnerability CVE-2023-43787 #2481

Closed
yarongol opened this issue Jan 25, 2024 · 3 comments · Fixed by #2589
Closed

Fixing Vulnerability CVE-2023-43787 #2481

yarongol opened this issue Jan 25, 2024 · 3 comments · Fixed by #2589

Comments

@yarongol
Copy link

yarongol commented Jan 25, 2024

Describe the bug

Here is the reported vulnerability

trivy image redocly/redoc --severity=HIGH
2024-01-25T09:12:28.440Z INFO Vulnerability scanning is enabled
......
redocly/redoc (alpine 3.18.4)

Total: 1 (HIGH: 1)

┌─────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬──────────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├─────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
│ libx11 │ CVE-2023-43787 │ HIGH │ fixed │ 1.8.4-r4 │ 1.8.7-r0 │ libX11: integer overflow in XCreateImage() leading to a heap │
│ │ │ │ │ │ │ overflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-43787
└─────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴──────────────────────────────────────────────────────────────┘

Please advise if redoc is sensitive to this vulnerability and when is the intended fix if relevant.
Thank you

@yarongol
Copy link
Author

yarongol commented Feb 6, 2024

Any feedback on this? Thanks.

@RomanHotsiy
Copy link
Member

Yes. We will take a look.

This vulnerability does not impact our docker container as this system function is not used by our code.

@yarongol
Copy link
Author

The response I got from a security advisor is:

It is clear that once someone takeover the container, Person can call the method and exploited the vulnerability even during code normal flow it won't get executed. Hence, vulnerabilities exist and exploitable"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants