@@ -118,6 +118,9 @@ LABEL name="NGINX Ingress Controller" \
118
118
119
119
COPY --link --chown=101:0 LICENSE /licenses/
120
120
121
+ # temp fix for CVE-2023-0361 and CVE-2021-46822
122
+ RUN microdnf --nodocs upgrade -y gnutls libjpeg-turbo
123
+
121
124
122
125
# ############################################ Base image for UBI with NGINX Plus #############################################
123
126
FROM redhat/ubi9-minimal AS ubi-plus
@@ -133,6 +136,8 @@ RUN --mount=type=secret,id=nginx-repo.crt,dst=/etc/ssl/nginx/nginx-repo.crt,mode
133
136
&& curl -fsSL "https://cs.nginx.com/static/files/plus-$(grep -E -o '[0-9]+\. [0-9]+' /etc/redhat-release | cut -d" ." -f1).repo" | tr 0 1 > /etc/yum.repos.d/nginx-plus.repo \
134
137
&& sed -i "0,/centos/s;;${NGINX_PLUS_VERSION}/centos;" /etc/yum.repos.d/nginx-plus.repo \
135
138
&& microdnf --nodocs install -y nginx-plus nginx-plus-module-njs \
139
+ # temp fix for CVE-2023-0361
140
+ && microdnf --nodocs upgrade -y gnutls \
136
141
&& microdnf remove -y shadow-utils \
137
142
&& microdnf clean all
138
143
@@ -169,7 +174,7 @@ RUN --mount=type=secret,id=nginx-repo.crt,dst=/etc/ssl/nginx/nginx-repo.crt,mode
169
174
dnf --nodocs install -y app-protect-dos; \
170
175
fi \
171
176
# fix for CVEs
172
- && dnf --nodocs upgrade -y libcom_err libxml2 krb5-libs dbus expat systemd libtasn1 sqlite-libs libksba platform-python platform-python-setuptools python3-setuptools-wheel tar \
177
+ && dnf --nodocs upgrade -y libcom_err libxml2 krb5-libs dbus expat systemd libtasn1 sqlite-libs libksba platform-python platform-python-setuptools python3-setuptools-wheel tar curl \
173
178
&& rm /etc/yum.repos.d/app-protect*.repo \
174
179
&& subscription-manager unregister \
175
180
&& dnf clean all && rm -rf /var/cache/dnf
0 commit comments