Uploaded image for project: 'Flink'
  1. Flink
  2. FLINK-23221

Migrate Docker images to Debian Bullseye

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 1.13.1
    • 1.11.4, 1.14.0, 1.12.5, 1.13.2
    • flink-docker
    • Issue was discovered by AWS ECR image scanning on apache/flink:1.13.1-scala_2.12

    Description

      The AWS ECR image scanning reports some HIGH vulnerabilities on apache/flink:1.13.1-scala_2.12 docker image. In addition, all versions prior to this one have these issues.

      The vulnerabilities are the following:

      1. CVE-2021-33574
      2. CVE-2019-25013 - for this one a patch was been released in glibc versionĀ 2.31-9

      Our security policy do not allow us to deploy images having security vulnerabilities. Searching through the Internet I found that for the first problem, a patch containing the solution will be release this year.

      Do you plan to release a new image containing the newer glibc version in order to solve those issues?

      Also, I checked and the alpine based flink images do not have these vulnerabilities. Do you plan to release newer versions of flink based on alpine (latest one is flink:1.8.x)?

      Attachments

        Activity

          People

            chesnay Chesnay Schepler
            Raszan Razvan AGAPE
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: