Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Log4j Vulnerability Fix - Docker Image #322

Closed
ecetiner87 opened this issue Dec 23, 2021 · 6 comments
Closed

Log4j Vulnerability Fix - Docker Image #322

ecetiner87 opened this issue Dec 23, 2021 · 6 comments

Comments

@ecetiner87
Copy link

Dear all,

As you know log4j vulnerability hits most of the applications during last 2 weeks. In our security scan; kafdrop-3.27 detected with this vulnerability. So we just moved it out from our current deployments but we really need it for our operation cycle.

Do you have any plan to update related vulnerable version in codebase and push a new docker image to dockerhub?

Best Regards

@kbudde
Copy link
Contributor

kbudde commented Dec 23, 2021

The fix was merged some hours ago to master: #320
But no new image was deployed to dockerhub.

@ekoutanov It looks like travis is not connected to github anymore.

@davideicardi
Copy link
Collaborator

Closed in favor of #323 .
But I agree, it is high priority to try to restore Travis or any other CI/CD and release docker image.

@ecetiner87
Copy link
Author

Thanks @davideicardi for notification. I will follow the progress with #323 .

Regards.

@davideicardi
Copy link
Collaborator

Published new docker image 3.28.0-SNAPSHOT with log4j fix.

@feli0821
Copy link

feli0821 commented Jan 5, 2022

@davideicardi , where can i get it? I see the last update for docker was 8months ago. Thanks.

@fazla86
Copy link

fazla86 commented Jan 5, 2022

@feli0821 you can see it on https://hub.docker.com/r/obsidiandynamics/kafdrop/tags?page=1&name=3.28.0-SNAPSHOT
docker pull obsidiandynamics/kafdrop:3.28.0-SNAPSHOT

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants