diff --git a/Dockerfile b/Dockerfile index c07c6f29da..fdc85831de 100644 --- a/Dockerfile +++ b/Dockerfile @@ -22,11 +22,20 @@ ARG POWERSHELL_SHA256_ARM64=2503b71da3e83635592b092df59a0aca4c3606b4d9b068217bb0 ARG ZIZMOR_SHA256_AMD64=a8000f3c683319a523d3b20df0e75457ba591f049cfcbfa98966631b56733c03 ARG ZIZMOR_SHA256_ARM64=d66e37ef8a375fb07939c630ebf9709a6e0f20242bdc3faf672a7ed97e0b768d +# High CVEs fixed in Debian trixie-security but not yet in the pinned base image: +# openssl/libssl3t64/openssl-provider-legacy 3.5.7-1~deb13u2 CVE-2026-14456, +# -14457, -18798, -54874, -63072, -63073, -63074, -63075, -63076, -75803 +# (image ships 3.5.6-1~deb13u2) +# Taken as a targeted --only-upgrade rather than by moving the digest: the newest +# published python:3.12-slim-trixie carries the same vulnerable version. The three +# packages are all built from openssl and are flagged separately, so all are named. +# Drop them once the base image ships 3.5.7-1~deb13u2 or later. # hadolint ignore=DL3008 RUN apt-get update && apt-get install -y --no-install-recommends \ wget libicu76 libunwind8 libssl3 libcurl4 ca-certificates apt-transport-https gnupg \ build-essential pkg-config libzstd-dev zlib1g-dev \ - && apt-get install -y --no-install-recommends --only-upgrade util-linux \ + && apt-get install -y --no-install-recommends --only-upgrade \ + util-linux libssl3t64 openssl openssl-provider-legacy \ && rm -rf /var/lib/apt/lists/* # Install PowerShell diff --git a/api/Dockerfile b/api/Dockerfile index 0f7e5883bb..6866494bb4 100644 --- a/api/Dockerfile +++ b/api/Dockerfile @@ -21,6 +21,14 @@ ARG POWERSHELL_SHA256_ARM64=2503b71da3e83635592b092df59a0aca4c3606b4d9b068217bb0 ARG ZIZMOR_SHA256_AMD64=a8000f3c683319a523d3b20df0e75457ba591f049cfcbfa98966631b56733c03 ARG ZIZMOR_SHA256_ARM64=d66e37ef8a375fb07939c630ebf9709a6e0f20242bdc3faf672a7ed97e0b768d +# High CVEs fixed in Debian trixie-security but not yet in the pinned base image: +# openssl/libssl3t64/openssl-provider-legacy 3.5.7-1~deb13u2 CVE-2026-14456, +# -14457, -18798, -54874, -63072, -63073, -63074, -63075, -63076, -75803 +# (image ships 3.5.6-1~deb13u2) +# Taken as a targeted --only-upgrade rather than by moving the digest: the newest +# published python:3.12-slim-trixie carries the same vulnerable version. The three +# packages are all built from openssl and are flagged separately, so all are named. +# Drop them once the base image ships 3.5.7-1~deb13u2 or later. # hadolint ignore=DL3008 RUN apt-get update && apt-get install -y --no-install-recommends \ wget \ @@ -36,7 +44,8 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ libtool \ libxslt1-dev \ python3-dev \ - && apt-get install -y --no-install-recommends --only-upgrade util-linux \ + && apt-get install -y --no-install-recommends --only-upgrade \ + util-linux libssl3t64 openssl openssl-provider-legacy \ && rm -rf /var/lib/apt/lists/* # Install PowerShell diff --git a/api/changelog.d/api-image-openssl-cves.security.md b/api/changelog.d/api-image-openssl-cves.security.md new file mode 100644 index 0000000000..9c3b2d5209 --- /dev/null +++ b/api/changelog.d/api-image-openssl-cves.security.md @@ -0,0 +1 @@ +`openssl`, `libssl3t64` and `openssl-provider-legacy` upgraded to 3.5.7-1~deb13u2 in the API container image, patching ten high OpenSSL CVEs diff --git a/prowler/changelog.d/sdk-image-openssl-cves.security.md b/prowler/changelog.d/sdk-image-openssl-cves.security.md new file mode 100644 index 0000000000..ef78982da5 --- /dev/null +++ b/prowler/changelog.d/sdk-image-openssl-cves.security.md @@ -0,0 +1 @@ +`openssl`, `libssl3t64` and `openssl-provider-legacy` upgraded to 3.5.7-1~deb13u2 in the SDK container image, patching ten high OpenSSL CVEs diff --git a/ui/Dockerfile b/ui/Dockerfile index 8669f801f4..a7ff72e65f 100644 --- a/ui/Dockerfile +++ b/ui/Dockerfile @@ -5,10 +5,27 @@ LABEL maintainer="https://github.com/prowler-cloud" # The build uses pnpm via corepack, so npm is unused — remove it (and npx) to drop # the bundled-npm CVE surface from every stage, incl. prod. -# No apk upgrade: it resolves against Alpine's live repo, so the digest pin above -# would not make the image reproducible. Move the digest forward instead. +# No blanket apk upgrade: it resolves against Alpine's live repo, so the digest pin +# above would not make the image reproducible. Move the digest forward instead, or +# take a named package as the targeted exception below. RUN corepack enable && rm -rf /usr/local/lib/node_modules/npm /usr/local/bin/npm /usr/local/bin/npx +# High CVEs fixed in Alpine 3.24 but not yet in the pinned base image: +# libcrypto3/libssl3 3.5.8-r0 CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, +# CVE-2026-54874, CVE-2026-63072, CVE-2026-63075, +# CVE-2026-63076 (image ships 3.5.7-r0) +# The base image pins node 24.18.1, which has not been rebuilt since that package +# was published, so the upgrade is taken here rather than by moving the pin -- the +# newest published node:24-alpine (24.19.0, built 2026-08-03) predates the +# 2026-08-13 advisory and carries the same vulnerable version. libcrypto3 and +# libssl3 are both built from openssl and are flagged separately, so both are named. +# `>=` rather than `=`: Alpine keeps only the newest build of a package in a +# branch's index, so an exact pin breaks this build the day 3.5.8-r0 is superseded. +# Drop this once the base image ships 3.5.8-r0 or later. +RUN apk add --no-cache --upgrade \ + "libcrypto3>=3.5.8-r0" \ + "libssl3>=3.5.8-r0" + # Install dependencies only when needed FROM base AS deps # Check https://github.com/nodejs/docker-node/tree/b4117f9333da4138b03a546ec926ef50a31506c3#nodealpine to understand why libc6-compat might be needed. diff --git a/ui/changelog.d/ui-image-openssl-cves.security.md b/ui/changelog.d/ui-image-openssl-cves.security.md new file mode 100644 index 0000000000..4e5ae59efc --- /dev/null +++ b/ui/changelog.d/ui-image-openssl-cves.security.md @@ -0,0 +1 @@ +`libcrypto3` and `libssl3` upgraded to 3.5.8-r0 in the UI container image, patching seven high OpenSSL CVEs