Skip to content

Conversation

@hibohra1398
Copy link

We have a critical vulnerability in our base image coming from busybox and fixed in version fixed in 1.35+
Updated base image sha to fix vulnerability (CVE-2022-48174) in busybox

docker run --rm --entrypoint /busybox/sh gcr.io/distroless/cc-debian12:debug@sha256:0a0d9b423154de754ee914ab1d3eefe8b394b08a8f21f96d75f8dec8e0d45df3 -c "/busybox/busybox"

BusyBox v1.37.0 (2024-09-26 21:31:42 UTC) multi-call binary.
BusyBox is copyrighted by many authors between 1998-2015.
Licensed under GPLv2. See source distribution for detailed
copyright notices.

Busybox present in this one is 1.37.0 and doesnt have this critical vulnerability

@hibohra1398 hibohra1398 closed this Nov 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant