You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We are currently using the postgres:13.20-alpine3.21 image for PostgreSQL in our environment. During our security review, we discovered multiple high and critical vulnerabilities present in the image. These vulnerabilities pose a significant risk to our system and need immediate attention.
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
stdlib go1.18.2 1.21.11, 1.22.4 go-module CVE-2024-24790 Critical
stdlib go1.18.2 1.19.10, 1.20.5 go-module CVE-2023-29405 Critical
stdlib go1.18.2 1.19.10, 1.20.5 go-module CVE-2023-29404 Critical
stdlib go1.18.2 1.19.10, 1.20.5 go-module CVE-2023-29402 Critical
stdlib go1.18.2 1.19.9, 1.20.4 go-module CVE-2023-24540 Critical
stdlib go1.18.2 1.19.8, 1.20.3 go-module CVE-2023-24538 Critical
stdlib go1.18.2 1.21.0-0 go-module CVE-2023-24531 Critical
stdlib go1.18.2 1.22.7, 1.23.1 go-module CVE-2024-34158 High
stdlib go1.18.2 1.22.7, 1.23.1 go-module CVE-2024-34156 High
stdlib go1.18.2 1.21.12, 1.22.5 go-module CVE-2024-24791 High
stdlib go1.18.2 1.21.8, 1.22.1 go-module CVE-2024-24784 High
stdlib go1.18.2 1.21.9, 1.22.2 go-module CVE-2023-45288 High
stdlib go1.18.2 1.20.0 go-module CVE-2023-45287 High
stdlib go1.18.2 1.20.12, 1.21.5 go-module CVE-2023-45285 High
stdlib go1.18.2 1.20.10, 1.21.3 go-module CVE-2023-44487 High
stdlib go1.18.2 1.20.9, 1.21.2 go-module CVE-2023-39323 High
stdlib go1.18.2 1.19.10, 1.20.5 go-module CVE-2023-29403 High
stdlib go1.18.2 1.19.9, 1.20.4 go-module CVE-2023-29400 High
stdlib go1.18.2 1.19.9, 1.20.4 go-module CVE-2023-24539 High
stdlib go1.18.2 1.19.8, 1.20.3 go-module CVE-2023-24537 High
stdlib go1.18.2 1.19.8, 1.20.3 go-module CVE-2023-24536 High
stdlib go1.18.2 1.19.8, 1.20.3 go-module CVE-2023-24534 High
stdlib go1.18.2 1.19.6 go-module CVE-2022-41725 High
stdlib go1.18.2 1.19.6 go-module CVE-2022-41724 High
stdlib go1.18.2 1.19.6 go-module CVE-2022-41723 High
stdlib go1.18.2 1.18.7, 1.19.2 go-module CVE-2022-41715 High
stdlib go1.18.2 1.17.13, 1.18.5 go-module CVE-2022-32189 High
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-30635 High
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-30633 High
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-30632 High
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-30631 High
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-30630 High
stdlib go1.18.2 1.17.11, 1.18.3 go-module CVE-2022-30580 High
stdlib go1.18.2 1.18.7, 1.19.2 go-module CVE-2022-2880 High
stdlib go1.18.2 1.18.7, 1.19.2 go-module CVE-2022-2879 High
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-28131 High
stdlib go1.18.2 1.18.6 go-module CVE-2022-27664 High
stdlib go1.18.2 1.22.12, 1.23.6, 1.24.0-rc.3 go-module CVE-2025-22866 Medium
stdlib go1.18.2 1.22.11, 1.23.5, 1.24.0-rc.2 go-module CVE-2024-45341 Medium
stdlib go1.18.2 1.22.11, 1.23.5, 1.24.0-rc.2 go-module CVE-2024-45336 Medium
stdlib go1.18.2 1.22.7, 1.23.1 go-module CVE-2024-34155 Medium
stdlib go1.18.2 1.21.11, 1.22.4 go-module CVE-2024-24789 Medium
stdlib go1.18.2 1.21.10, 1.22.3 go-module CVE-2024-24787 Medium
stdlib go1.18.2 1.21.8, 1.22.1 go-module CVE-2024-24783 Medium
stdlib go1.18.2 1.21.8, 1.22.1 go-module CVE-2023-45290 Medium
stdlib go1.18.2 1.21.8, 1.22.1 go-module CVE-2023-45289 Medium
stdlib go1.18.2 1.20.12, 1.21.5 go-module CVE-2023-39326 Medium
stdlib go1.18.2 1.20.8, 1.21.1 go-module CVE-2023-39319 Medium
stdlib go1.18.2 1.20.8, 1.21.1 go-module CVE-2023-39318 Medium
stdlib go1.18.2 1.19.12, 1.20.7 go-module CVE-2023-29409 Medium
stdlib go1.18.2 1.19.11, 1.20.6 go-module CVE-2023-29406 Medium
stdlib go1.18.2 1.19.7, 1.20.2 go-module CVE-2023-24532 Medium
stdlib go1.18.2 1.18.9, 1.19.4 go-module CVE-2022-41717 Medium
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-32148 Medium
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-1962 Medium
stdlib go1.18.2 1.17.12, 1.18.4 go-module CVE-2022-1705 Medium
stdlib go1.18.2 1.17.11, 1.18.3 go-module CVE-2022-30629 Low
stdlib go1.18.2 1.21.8, 1.22.1 go-module CVE-2024-24785 Unknown
The vulnerabilities impact system integrity, data security, and could potentially lead to system compromises.
Steps to Reproduce:
Pull the postgres:13.20-alpine3.21 image from Docker Hub.
Run a security scan on the image (using tools like Trivy, Clair, etc.).
Review the results, which show several high and critical vulnerabilities.
Expected Behavior:
The image should be free from critical vulnerabilities to ensure secure deployment in production environments.
Current Behavior:
The postgres:13.20-alpine3.21 image contains multiple high and critical vulnerabilities.
The text was updated successfully, but these errors were encountered:
We are currently using the postgres:13.20-alpine3.21 image for PostgreSQL in our environment. During our security review, we discovered multiple high and critical vulnerabilities present in the image. These vulnerabilities pose a significant risk to our system and need immediate attention.
Affected Version:
PostgreSQL Image Version: postgres:13.20-alpine3.21
Vulnerabilities Identified:
Another Security Tool Result
The vulnerabilities impact system integrity, data security, and could potentially lead to system compromises.
Steps to Reproduce:
Pull the postgres:13.20-alpine3.21 image from Docker Hub.
Run a security scan on the image (using tools like Trivy, Clair, etc.).
Review the results, which show several high and critical vulnerabilities.
Expected Behavior:
The image should be free from critical vulnerabilities to ensure secure deployment in production environments.
Current Behavior:
The postgres:13.20-alpine3.21 image contains multiple high and critical vulnerabilities.
The text was updated successfully, but these errors were encountered: