【详述】问题详细描述
扫出了一些安全漏洞, 咨询下官方能否修复?
【是否存算分离】否
【StarRocks版本】3.2.7
请问扫描的是具体哪个镜像?
starrocks/fe-ubuntu:latest和starrocks/be-ubuntu:latest 3.2.7版本
https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.16
curl 7.81.0 on ubuntu22.04 should be patched with the CVE fixes. It is not necessary to be updated to v8.4.0
those apache log4j security issues, please open a github issue, will have someone to address that.
@cmptmn你开一个github issue, 我assign给你.
感谢!
是的, 扫出libcurl7.69的那个漏洞是具体是这个: https://curl.se/docs/CVE-2023-38545.html
在ubuntu上7.81.0-1ubuntu1.14就修了. Ubuntu22.04是LTS版本, 基本的安全漏洞都会有及时的版本更新.
curl (7.81.0-1ubuntu1.16) jammy-security; urgency=medium
* SECURITY UPDATE: HTTP/2 push headers memory-leak
- debian/patches/CVE-2024-2398.patch: push headers better cleanup in
lib/http2.c.
- CVE-2024-2398
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 19 Mar 2024 08:16:19 -0400
curl (7.81.0-1ubuntu1.15) jammy-security; urgency=medium
* SECURITY UPDATE: cookie mixed case PSL bypass
- debian/patches/CVE-2023-46218.patch: lowercase the domain names
before PSL checks in lib/cookie.c.
- CVE-2023-46218
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Wed, 29 Nov 2023 14:23:00 -0500
curl (7.81.0-1ubuntu1.14) jammy-security; urgency=medium
* SECURITY UPDATE: SOCKS5 heap buffer overflow
- debian/patches/CVE-2023-38545.patch: return error if hostname too
long for remote resolve in lib/socks.c, tests/data/Makefile.inc,
tests/data/test728.
- CVE-2023-38545
* SECURITY UPDATE: cookie injection with none file
- debian/patches/CVE-2023-38546.patch: remove unnecessary struct fields
in lib/cookie.c, lib/cookie.h, lib/easy.c.
- CVE-2023-38546
-- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 03 Oct 2023 13:15:41 -0400
我今天可以提RP。至于镜像由StarRocks官方发的,可能不会这么快发的。log1.2.17是由hudi-common0.14.1间接依赖引入的,log4j2.19.0有log1.2的兼容API,所以log1.2.7的包不是必须的。如果你如果急着修复漏洞可以在fe/lib下把log4j-1.2.17.jar的包删了。
好的,辛苦老师提下RP, 代码仓库帮发下
@lvlouisaslia 老师 意思是我上面发的截图中的安全漏洞 在starrocks3.2.6及以上版本都没问题, 我现在用的就是starrocks3.2.7, 为什么还是扫出libcurl的安全漏洞,请教下具体如何处理
得看你的安全工具了.
搞定了 