Skip to content
Discussion options

You must be logged in to vote

WIZ security scanner is falsely reporting that bottlerocket-aws-ecs-2-aarch64-v1.42.0-5ed15786 is vulnerable to GHSA-265r-hfxg-fhmg, even though the deployed containerd version already patched the issue.

That variant is on containerd 1.7.27 which is the patched version. I'm curious to know what logic Wiz is using to flag this because this should be a straighforward case where the version is the patched version for that CVE. I'd recommend asking them specifically since I can't speak to how they are detecting this.

One idea would be to explicitly use containerd 2 and I found a PR that integrated support for it (bottlerocket-os/bottlerocket-core-kit#485 and #4375), but it looks like it's …

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@FalkWoldmann
Comment options

Answer selected by FalkWoldmann
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants