-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Open
Labels
Description
Expected Behavior
No more CVEs found
Actual Behavior
There are some CVEs found from the latest Temporal image:
temporalio/admin-tools:1.29.1*
Steps to Reproduce the Problem
Pull the latest image temporalio/admin-tools:1.29.1* from Dockerhub
Scan the image with any vulnerability scanner
| CVE | SEVERITY | CVSS | PACKAGE | VERSION | FIX IN |
|---|---|---|---|---|---|
| CVE-2025-22870, CWE-918 | HIGH | 8.8 | golang.org/x/net/http/httpproxy | v0.34.0 | 0.36.0 |
| CVE-2023-47108, CWE-770, GHSA-8pgv-569h-w5rw | HIGH | 7.5 | go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc | v0.36.4 | 0.46.0 |
| CVE-2024-44337, CWE-835 | MEDIUM | 6.9 | github.com/gomarkdown/markdown/parser | v0.0.0-20250311123330-531bef5e742b | N/A |
| CVE-2024-2689, CWE-20, GHSA-wmxc-v39r-p9wf | MEDIUM | 4.4 | go.temporal.io/server/common | v1.18.1-0.20230217005328-b313b7f58641 | 1.20.5 |
| CVE-2025-9086 | LOW | None | curl | 8.14.1-r0 | 8.14.1-r2 |
| CVE-2025-10148 | LOW | None | curl | 8.14.1-r0 | 8.14.1-r2 |
| CVE-2025-4575 | LOW | None | openssl | 3.5.0-r0 | 3.5.1-r0 |
| CVE-2025-9232 | LOW | None | openssl | 3.5.0-r0 | 3.5.4-r0 |
| CVE-2025-9230 | LOW | None | openssl | 3.5.0-r0 | 3.5.4-r0 |
| CVE-2025-9231 | LOW | None | openssl | 3.5.0-r0 | 3.5.4-r0 |
| CVE-2025-8715 | LOW | None | postgresql | 17:17.5-r0 | 17.6-r0 |
| CVE-2025-8714 | LOW | None | postgresql | 17:17.5-r0 | 17.6-r0 |
| CVE-2025-8713 | LOW | None | postgresql | 17:17.5-r0 | 17.6-r0 |
| CVE-2025-12817 | LOW | None | postgresql | 17:17.5-r0 | 17.7-r0 |
| CVE-2025-12818 | LOW | None | postgresql | 17:17.5-r0 | 17.7-r0 |
| CVE-2025-59375, CWE-770 | LOW | None | expat | 2.7.1-r0 | 2.7.2-r0 |
| CVE-2025-49014, CWE-416 | LOW | None | jq | 1.8.0-r0 | 1.8.1-r0 |
| CVE-2025-6965 | CRITICAL | 9.8 | sqlite | 3.49.2-r0 | 3.49.2-r1 |