Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-2744

Vulnerabilities for Debian and Alpine based images are marked as unknown, Ubuntu vulnerabilities not detected

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • clair, quay
    • False
    • False
    • Quay Enterprise

      The images I tried are:

      library/alpine/k8s:1.20.7
      library/drupal:latest
      library/drupal:8.4.0-rc1 (4 years old)

      In all three images, Quay shows all detected vulnerabilities as Unknown. When I open Drupal's latest to check on those 200 vulnerabilities, all vulnerabilities say the issue is Fixed in 0:0. Some vulnerabilities have the correct CVE information attached along with the CVSSv3 score but they still show as unknown. Even those that are marked as high.

      It would also appear that detection of vulnerabilities is still not correct. The image library/mariadb:10.6.3-focal turns up with 0 vulnerabilities in Quay 3.6.0. Quay.io on the other hand for the same image detects 69 vulnerabilities, of which 1 is high, 48 are medium. And patches are available for 51.

      Image on quay.io: https://quay.io/repository/ibazulic1/mariadb?tab=tags

      Please see attached screenshots. Thank you!

        1. firefox_ZrLoY5rUCN.png
          firefox_ZrLoY5rUCN.png
          51 kB
        2. firefox_ZEnAWyl1eH-1.png
          firefox_ZEnAWyl1eH-1.png
          38 kB
        3. firefox_DngSs65hSg-1.png
          firefox_DngSs65hSg-1.png
          23 kB
        4. firefox_CTPecf9RFe-1.png
          firefox_CTPecf9RFe-1.png
          52 kB
        5. firefox_cNuSvC8nNR.png
          firefox_cNuSvC8nNR.png
          42 kB
        6. firefox_bBckcRHasV.png
          firefox_bBckcRHasV.png
          63 kB
        7. firefox_5RpHpAPqLa.png
          firefox_5RpHpAPqLa.png
          35 kB
        8. chrome_ZnxfrQa0AP.png
          chrome_ZnxfrQa0AP.png
          41 kB
        9. chrome_dLxSgEkYo4.png
          chrome_dLxSgEkYo4.png
          85 kB

              jcroslan@redhat.com Joseph Crosland
              rhn-support-ibazulic Ivan Bazulic
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: