<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Several vulnerabilities in ACS docker images 7.0.1 and 7.1.0 detected by Trivy in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128191#M34783</link>
    <description>&lt;P&gt;Thanks for the detailed report, Jens.&lt;/P&gt;
&lt;P&gt;We are using different tools in order to identify vulnerabilities in our Docker Images. This process is proactively used for every release, but there may be something we're missing.&lt;/P&gt;
&lt;P&gt;Let me verify the impact of the vulnerabilities identified by Trivy and I'll be back with additional information.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Nov 2021 08:37:45 GMT</pubDate>
    <dc:creator>angelborroy</dc:creator>
    <dc:date>2021-11-02T08:37:45Z</dc:date>
    <item>
      <title>Several vulnerabilities in ACS docker images 7.0.1 and 7.1.0 detected by Trivy</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128189#M34781</link>
      <description>&lt;P&gt;We are using the provided alfresco enterprise containers to deploy Alfresco&amp;nbsp; in the Azure Kubernetes Cluster.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In terms of container security we are using trivy to scan the images for&amp;nbsp;vulnerabilities.&lt;/P&gt;&lt;P&gt;We have used trivy to scan the acs image in version 7.0.1 with following command:&lt;/P&gt;&lt;PRE&gt;trivy -d quay.io/alfresco/alfresco-content-repository:7.0.1&lt;/PRE&gt;&lt;P&gt;The result is:&lt;/P&gt;&lt;PRE&gt;quay.io/alfresco/alfresco-content-repository:7.0.1 (centos 8.4.2105)
====================================================================
Total: 337 (UNKNOWN: 0, LOW: 139, MEDIUM: 178, HIGH: 16, CRITICAL: 4)&lt;/PRE&gt;&lt;P&gt;Even the new Alfresco Content repository 7.1.0 image has several known security issues, even more than the older version.&lt;/P&gt;&lt;PRE&gt;quay.io/alfresco/alfresco-content-repository:7.1.0 (centos 7.9.2009)
====================================================================
Total: 810 (UNKNOWN: 0, LOW: 410, MEDIUM: 389, HIGH: 9, CRITICAL: 2)&lt;/PRE&gt;&lt;P&gt;Fun fact: For the newer version of acs there is a os-downgrade to centos 7.9 (instead of centos 8.4 in acs-7.0.1), so it would explain the higher number of issues.&lt;/P&gt;&lt;P&gt;For me these results are not acceptable as we need to deploy a docker container of an Enterprise software on a customer platform with high and critical issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/5487"&gt;@angelborroy&lt;/A&gt;&amp;nbsp;: Do you know more about the process behind docker container updates and fixing security issues? Do you already scan your docker images for security issues? Do you know where to submit these issues- In the github project &lt;A href="https://github.com/Alfresco/acs-packaging/" target="_blank" rel="noopener nofollow noreferrer"&gt;https://github.com/Alfresco/acs-packaging/&lt;/A&gt; or as support ticket?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 14:29:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128189#M34781</guid>
      <dc:creator>jego</dc:creator>
      <dc:date>2021-11-01T14:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Several vulnerabilities in ACS docker images 7.0.1 and 7.1.0 detected by Trivy</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128190#M34782</link>
      <description>&lt;P&gt;In general, you can open issue here:&amp;nbsp;&lt;A href="https://github.com/Alfresco/acs-packaging/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://github.com/Alfresco/acs-packaging/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/86605"&gt;@amanda_roberts&lt;/A&gt;&amp;nbsp;or &lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/5487"&gt;@angelborroy&lt;/A&gt;&amp;nbsp;May be able to direct you to a correct channel to open the ticket with support and followups.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 20:12:49 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128190#M34782</guid>
      <dc:creator>abhinavmishra14</dc:creator>
      <dc:date>2021-11-01T20:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Several vulnerabilities in ACS docker images 7.0.1 and 7.1.0 detected by Trivy</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128191#M34783</link>
      <description>&lt;P&gt;Thanks for the detailed report, Jens.&lt;/P&gt;
&lt;P&gt;We are using different tools in order to identify vulnerabilities in our Docker Images. This process is proactively used for every release, but there may be something we're missing.&lt;/P&gt;
&lt;P&gt;Let me verify the impact of the vulnerabilities identified by Trivy and I'll be back with additional information.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 08:37:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128191#M34783</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2021-11-02T08:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Several vulnerabilities in ACS docker images 7.0.1 and 7.1.0 detected by Trivy</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128192#M34784</link>
      <description>&lt;P&gt;I have also created a support case - thenumber is 00556732- maybe you can have a look into it because there are some answers already from Scott.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 09:28:24 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128192#M34784</guid>
      <dc:creator>jego</dc:creator>
      <dc:date>2021-11-02T09:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Several vulnerabilities in ACS docker images 7.0.1 and 7.1.0 detected by Trivy</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128193#M34785</link>
      <description>&lt;P&gt;Great &lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/29400"&gt;@jego&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll follow this case.&lt;/P&gt;
&lt;P&gt;Since we are using different vulnerability tools, I guess we should need to identify those reports from Trivy.&lt;/P&gt;
&lt;P&gt;Additionally, the move to CentOS 8 to CentOS 7 was related with CentOS 8 EOL for December 2021:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.centos.org/centos-linux-eol/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.centos.org/centos-linux-eol/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 10:07:59 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/several-vulnerabilities-in-acs-docker-images-7-0-1-and-7-1-0/m-p/128193#M34785</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2021-11-02T10:07:59Z</dc:date>
    </item>
  </channel>
</rss>

