Thanks. Some of the vulnerabilities doesn't apply to us (for example the spring vulnerability that only affects JSP), but I don't suppose these scanners would be able to make such a distinction.
I'll file this as a SECURITY ticket so that the team can discuss any legitimate issues that need fixing, as well as whether anything can be done to avoid scaring users about vulnerabilities that do not apply. On Wed, Jun 15, 2016 at 1:05 AM Carlos Sanchez <[email protected]> wrote: > Hi, > > The last docker image for 1.651.3 is up in the docker hub. > > The official images are now security scanned, and you can see the results > at https://hub.docker.com/r/library/jenkins/tags/1.651.3/ (need to be > logged in) > > Some layers come from the parent Debian and Java images, but the last ones > are from Jenkins war, showing several CVEs for Spring (critical), Groovy > (critical), httpclient, commons-compress, xstream and jbcrypt > > -- > You received this message because you are subscribed to the Google Groups > "Jenkins Developers" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > To view this discussion on the web visit > https://groups.google.com/d/msgid/jenkinsci-dev/caf20fac-70d0-4429-8335-ed3366105982%40googlegroups.com > <https://groups.google.com/d/msgid/jenkinsci-dev/caf20fac-70d0-4429-8335-ed3366105982%40googlegroups.com?utm_medium=email&utm_source=footer> > . > For more options, visit https://groups.google.com/d/optout. > -- You received this message because you are subscribed to the Google Groups "Jenkins Developers" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/CAN4CQ4zz4rzg5_%2B0w02if-C%2B1p6HC4YY%2BLWAV8MFH5NjEmm5bQ%40mail.gmail.com. For more options, visit https://groups.google.com/d/optout.
