Uploaded image for project: 'FOLIO'
  1. FOLIO
  2. FOLIO-3402

folioci/alpine-jre-openjdk11 not affected by polkit (CVE-2021-4034)

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • TBD
    • Resolution: Cannot Reproduce
    • None
    • FOLIO DevOps
    • TBD

    Description

      folioci/alpine-jre-openjdk11 = https://github.com/folio-org/folio-tools/blob/master/folio-java-docker/openjdk11/Dockerfile

      Most FOLIO Java modules use this Docker image that is based on Alpine.

      However, our image doesn't contain the polkit Alpine package.

      Therefore it is not affected by this Local Privilege Escalation in polkit's pkexec:
      https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
      https://security.alpinelinux.org/srcpkg/polkit

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                Unassigned Unassigned
                julianladisch Julian Ladisch
                Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases