diff --git a/.trivyignore.yaml b/.trivyignore.yaml index 715c7b625e..efac339352 100644 --- a/.trivyignore.yaml +++ b/.trivyignore.yaml @@ -130,36 +130,6 @@ vulnerabilities: - "pkg:npm/ip-address" expired_at: 2027-01-31 - # CVE-2026-62901 is a DoS in System.Net.WebSockets (unchecked input for loop condition, - # CWE-606), fixed in .NET 9.0.19 / 10.0.11 (published 2026-08-11). The vulnerable runtime - # ships inside the PowerShell tarball the Dockerfile pins: 7.5.9 is the latest 7.5.x and - # bundles .NET 9.0.18; 7.6.4 bundles .NET 10.0.x < 10.0.11, so no published PowerShell - # release contains the fix yet. Prowler only invokes pwsh locally to run M365 module - # cmdlets; the image does not accept inbound WebSocket connections, so the DoS path is - # not reachable from the network. Remove this temporary suppression as soon as a - # PowerShell release shipping .NET 9.0.19+ is available. - - id: CVE-2026-62901 - purls: - - "pkg:nuget/Microsoft.NETCore.App.Runtime.linux-x64" - - "pkg:nuget/Microsoft.NETCore.App.Runtime.linux-arm64" - expired_at: 2026-09-15 - - # Modules compiled into the Trivy binary the images ship. The binary is pinned by version - # and verified by checksum in the Dockerfile; only a rebuild by its vendor moves these. - # CVE-2026-71556 affects go-git worktree operations that can follow symlinks outside a - # cloned repository. Trivy 0.73.0, the latest published release and the version the - # images ship, still pins that vulnerable version: - # https://github.com/aquasecurity/trivy/blob/v0.73.0/go.mod#L46 - # Trivy main already contains the 5.19.2 fix, but no published release includes it yet: - # https://github.com/aquasecurity/trivy/commit/a2edba9a03987ba0d2ebc8212c1a9a1e6979497b - # Prowler invokes Trivy only with `fs` on an existing local path or with `image`; it does - # not ask Trivy to clone or mutate a Git worktree, so the affected path is not reachable. - # Remove this temporary suppression as soon as a fixed Trivy release is available. - - id: CVE-2026-71556 - purls: - - "pkg:golang/github.com/go-git/go-git/v5" - expired_at: 2026-09-15 - # CVE-2026-84304 is a DoS in grpc-go <= 1.83.0: a peer fragments a gRPC stream into # millions of tiny HTTP/2 DATA frames until the receiver runs out of heap. Fixed in # 1.83.1 (published 2026-09-01). Trivy 0.74.0, the latest published release and the diff --git a/Dockerfile b/Dockerfile index 559b39c9eb..dc62fd64a6 100644 --- a/Dockerfile +++ b/Dockerfile @@ -3,7 +3,7 @@ FROM python:3.12.13-slim-trixie@sha256:57cd7c3a7a273101a6485ba99423ee56815788280 LABEL maintainer="https://github.com/prowler-cloud/prowler" LABEL org.opencontainers.image.source="https://github.com/prowler-cloud/prowler" -ARG POWERSHELL_VERSION=7.5.9 +ARG POWERSHELL_VERSION=7.5.11 ENV POWERSHELL_VERSION=${POWERSHELL_VERSION} # Opt out of PowerShell telemetry (Application Insights -> dc.services.visualstudio.com) ENV POWERSHELL_TELEMETRY_OPTOUT=1 @@ -17,8 +17,8 @@ ENV ZIZMOR_VERSION=${ZIZMOR_VERSION} # Pinned here, not fetched with the artefact: a compromised release ships its own checksum. ARG TRIVY_SHA256_AMD64=2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a ARG TRIVY_SHA256_ARM64=b94ce1976bbf3c15b514b605ee88be7c6d94a29be2302847ff01cb794d47aad5 -ARG POWERSHELL_SHA256_AMD64=492ff26bb958336bf61e597ce19e07648b4003bd2a08659e02f0e3e0446ebfe0 -ARG POWERSHELL_SHA256_ARM64=2503b71da3e83635592b092df59a0aca4c3606b4d9b068217bb00be989cb0d56 +ARG POWERSHELL_SHA256_AMD64=82a8b13d92b0f3ae48e56cf2f3f7961679371736ca90145ca71617c2913ba9d8 +ARG POWERSHELL_SHA256_ARM64=830ebda118c731ece3fa7e6b7e8573a21346387cbbca5b2f5e3b9bfe24f96672 ARG ZIZMOR_SHA256_AMD64=a8000f3c683319a523d3b20df0e75457ba591f049cfcbfa98966631b56733c03 ARG ZIZMOR_SHA256_ARM64=d66e37ef8a375fb07939c630ebf9709a6e0f20242bdc3faf672a7ed97e0b768d diff --git a/api/Dockerfile b/api/Dockerfile index ce5bccbb2c..2262bd00d6 100644 --- a/api/Dockerfile +++ b/api/Dockerfile @@ -2,7 +2,7 @@ FROM python:3.12.13-slim-trixie@sha256:57cd7c3a7a273101a6485ba99423ee56815788280 LABEL maintainer="https://github.com/prowler-cloud/api" -ARG POWERSHELL_VERSION=7.5.9 +ARG POWERSHELL_VERSION=7.5.11 ENV POWERSHELL_VERSION=${POWERSHELL_VERSION} # Opt out of PowerShell telemetry (Application Insights -> dc.services.visualstudio.com) ENV POWERSHELL_TELEMETRY_OPTOUT=1 @@ -16,8 +16,8 @@ ENV ZIZMOR_VERSION=${ZIZMOR_VERSION} # Pinned here, not fetched with the artefact: a compromised release ships its own checksum. ARG TRIVY_SHA256_AMD64=2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a ARG TRIVY_SHA256_ARM64=b94ce1976bbf3c15b514b605ee88be7c6d94a29be2302847ff01cb794d47aad5 -ARG POWERSHELL_SHA256_AMD64=492ff26bb958336bf61e597ce19e07648b4003bd2a08659e02f0e3e0446ebfe0 -ARG POWERSHELL_SHA256_ARM64=2503b71da3e83635592b092df59a0aca4c3606b4d9b068217bb00be989cb0d56 +ARG POWERSHELL_SHA256_AMD64=82a8b13d92b0f3ae48e56cf2f3f7961679371736ca90145ca71617c2913ba9d8 +ARG POWERSHELL_SHA256_ARM64=830ebda118c731ece3fa7e6b7e8573a21346387cbbca5b2f5e3b9bfe24f96672 ARG ZIZMOR_SHA256_AMD64=a8000f3c683319a523d3b20df0e75457ba591f049cfcbfa98966631b56733c03 ARG ZIZMOR_SHA256_ARM64=d66e37ef8a375fb07939c630ebf9709a6e0f20242bdc3faf672a7ed97e0b768d diff --git a/api/changelog.d/api-image-powershell-dotnet-cve.security.md b/api/changelog.d/api-image-powershell-dotnet-cve.security.md new file mode 100644 index 0000000000..28b91a32a0 --- /dev/null +++ b/api/changelog.d/api-image-powershell-dotnet-cve.security.md @@ -0,0 +1 @@ +PowerShell from 7.5.9 to 7.5.11 in the API container image, bundling .NET runtime 9.0.20 and patching CVE-2026-62901 diff --git a/prowler/changelog.d/sdk-image-powershell-dotnet-cve.security.md b/prowler/changelog.d/sdk-image-powershell-dotnet-cve.security.md new file mode 100644 index 0000000000..370aa37289 --- /dev/null +++ b/prowler/changelog.d/sdk-image-powershell-dotnet-cve.security.md @@ -0,0 +1 @@ +PowerShell from 7.5.9 to 7.5.11 in the SDK container image, bundling .NET runtime 9.0.20 and patching CVE-2026-62901