Hello,
We have deployed v1.4.3 in our environment and our security scan through twistlock has identified lots of high and important security vulnerabilities in splunk connect for K8s. Following are the CVE ids for the vulnerabilities. Are these going to be addressed? If so, what is the timeline?
CVE-2018-1000500
CVE-2020-14363
CVE-2020-8252
CVE-2020-25613
CVE-2020-10663
CVE-2020-8116
CVE-2020-15999
Any news? Our security officers also complain due to the high number of CVEs.
I looked into this last December and created this image rock1017/fluentd-hec-27-2:1.2.4 with fixes available at the time. There are some vulnerabilities with not available fix yet. we will be updating our image as they become available. Thanks
@rockb1017 thanks. some programs were upgraded (npm, node, ruby, ..). still there is a massive number of issues in a huge red hat enterprise 8.3 image (by jfrog xrays count unfortunately even more than in the official 1.2.4. image, whyever that might be).
i reckon as kubernetes is prevailing in more traditional, heavily regulated industries, demand to conform to more rigorous (security-)standards will rise. and maybe switching to a lightweigt, more secure base-image will be necessary as well.
i think splunk needs to improve there quite a bit.
We see similar issue. Having splunk with CVE which has fix in production will be really security issue.
we have latest 1.4.4
fixed_version | name | package_name | package_version | score | score_v3 | severity
-- | -- | -- | -- | -- | -- | --
1:12.18.2-1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:12.16.1-2.module+el8.1.0+6117+b25a342c | RHSA-2020:1293 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 6.8 | 8.8 | High
1:12.19.1-1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1:12.16.1-1.module+el8.1.0+5811+44509afe | RHSA-2020:0598 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 7.5 | 9.8 | High
1:12.18.4-2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:12.18.2-1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:12.19.1-1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1:12.18.4-2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:6.14.6-1.12.18.4.2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:6.14.5-1.12.18.2.1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:6.14.8-1.12.19.1.1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1.16.1-3.module+el8.0.0+3250+4b7d6d43 | RHSA-2019:1972 | rubygem-bundler | 1.16.1-3.module+el8+2671+ebcc7ee0 | 6.8 | 8.8 | High
=4.2.1;<5.0.0; OR >=5.1.1 | CVE-2020-8116 | usr/lib/node_modules/npm/node_modules/dot-prop/package.json | 4.2.0 | 7.5 | 7.3 | High
=5.2.4.3,5.2; OR >=6.0.3.1 | CVE-2020-8165 | usr/share/gems/specifications/activesupport-5.2.4.3 | 5.2.4.3 | 7.5 | 9.8 | High
=1.6.1 | CVE-2020-25613 | usr/share/gems/specifications/default/webrick-1.4.2 | 1.4.2 | 5 | 7.5 | High
=2.3.0 | CVE-2020-10663 | usr/share/gems/specifications/json-2.1.0 | 2.1.0 | 5 | 7.5 | High
=12.3.3 | CVE-2020-8130 | usr/share/gems/specifications/rake-12.3.0 | 12.3.0 | 9.3 | 8.1 | High
Hello @niteenkole
our latest image has node version 14.15.1 and npm 6.14.8.
your table says it has nodejs 10.21.0 and npm 6.14.4?
docker run -it splunk/fluentd-hec:1.2.4 bash
bash-4.4$ node --version
v14.15.1
bash-4.4$ npm --version
6.14.8
Hello @florianzimm
Thanks for your comment.
Do you have any examples of building fluentd application without vulnerabilities?
@rockb1017
I am sure we have below.
NAME NAMESPACE REVISION UPDATED STATUS CHART APP VERSION
splunk-connect-dev splunk 1 2021-01-13 11:16:05.501985101 -0500 EST deployed splunk-connect-for-kubernetes-1.4.4 1.4.4
describe on pod
Containers:
splunk-fluentd-k8s-logs:
Container ID: containerd://80b762040df74119564240afb234d815xxxxxxxxxx
Image: docker.io/splunk/fluentd-hec:1.2.4
kubectl exec -it splunk-connect-dev-splunk-kubernetes-logging-8h5qf -n splunk -- sh
sh-4.4# node --version
v10.21.0
sh-4.4# npm --version
6.14.4
have installed 1.4.4 as below
helm install splunk-connect-dev -f niteen-vaules-07.yaml -n splunk https://github.com/splunk/splunk-connect-for-kubernetes/releases/download/1.4.4/splunk-connect-for-kubernetes-1.4.4.tgz
could you do fresh pull from dockerhub ?
docker pull splunk/fluentd-hec:1.2.4
sure. I can restart pod which should pull latest splunk/fluentd-hec:1.2.4 and scan
you need to check below.
docker run -it splunk/fluentd-hec:1.2.4 bash
Unable to find image 'splunk/fluentd-hec:1.2.4' locally
Trying to pull repository registry.access.redhat.com/splunk/fluentd-hec ...
Pulling repository registry.access.redhat.com/splunk/fluentd-hec
Trying to pull repository docker.io/splunk/fluentd-hec ...
1.2.4: Pulling from docker.io/splunk/fluentd-hec
d9e72d058dc5: Pull complete
cca21acb641a: Pull complete
620696f92fec: Pull complete
a108724c930f: Pull complete
743be1bee877: Pull complete
0fd70c8f2a2f: Pull complete
93c7a9ad1e0b: Pull complete
b9f59c896a8e: Pull complete
da9c9c102637: Pull complete
3b3a1f6705fe: Pull complete
88312b755c95: Pull complete
Digest: sha256:9a068dc1c083b612b0fdc4c62fd06f11a0aa45dd17c5b7db2fc9a0c92d8cf927
Status: Downloaded newer image for docker.io/splunk/fluentd-hec:1.2.4
bash-4.4$ node --version
v10.21.0
bash-4.4$ npm --version
6.14.4
bash-4.4$
may be you have local image ?
omg. I think that is only possible explanation. lol
could you use rock1017/fluentd-hec-27-2:1.2.4 this image? it is same image under my dockerhub account.
I will work on releasing new image, but it takes time to officially release to splunk account.
Thank you!
Sure ,I will update my deployment to point to rock1017/fluentd-hec-27-2:1.2.4 run scan and update.
Hi,
image is now docker.io/rock1017/fluentd-hec-27-2:1.2.4
Way better :)
fixed_version | name | package_name | package_version | published_timestamp | score | score_v3 | severity
-- | -- | -- | -- | -- | -- | -- | --
3.6.14-7.el8_3 | RHSA-2020:5483 | gnutls | 3.6.14-6.el8 | 1599232500 | 5 | 7.5 | High
12.5-1.el8_3 | RHSA-2020:5401 | libpq | 12.4-1.el8_2 | 1605489300 | 6.8 | 8.1 | High
12.5-1.el8_3 | RHSA-2020:5401 | libpq-devel | 12.4-1.el8_2 | 1605489300 | 6.8 | 8.1 | High
3.1.11-2.el8_3 | RHSA-2020:5503 | mariadb-connector-c | 3.0.7-1.el8 | 1590002100 | 6.8 | 8.8 | High
3.1.11-2.el8_3 | RHSA-2020:5503 | mariadb-connector-c-config | 3.0.7-1.el8 | 1590002100 | 6.8 | 8.8 | High
3.1.11-2.el8_3 | RHSA-2020:5503 | mariadb-connector-c-devel | 3.0.7-1.el8 | 1590002100 | 6.8 | 8.8 | High
1:1.1.1g-12.el8_3 | RHSA-2020:5476 | openssl-devel | 1:1.1.1g-11.el8 | 1607444100 | 4.3 | 5.9 | Medium
1:1.1.1g-12.el8_3 | RHSA-2020:5476 | openssl-libs | 1:1.1.1g-11.el8 | 1607444100 | 4.3 | 5.9 | Medium
we see 1.4.5 released today which still has docker.io/splunk/fluentd-hec:1.2.4 ?
We going to collect security logs from cluster and your image will introduce more CVE in our env with every release splunk don't take care of cve with fix and fix them and then release ?
the new 1.2.4 ist way better, the tag was just not incremented.
@florianzimm I don't think so, I see below same as 1.4.4
fixed_version | name | package_name | package_version | score | score_v3 | severity
-- | -- | -- | -- | -- | -- | --
1:12.18.2-1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:12.16.1-1.module+el8.1.0+5811+44509afe | RHSA-2020:0598 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 7.5 | 9.8 | High
1:12.19.1-1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1:12.16.1-2.module+el8.1.0+6117+b25a342c | RHSA-2020:1293 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 6.8 | 8.8 | High
1:12.18.4-2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:12.19.1-1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1:12.18.2-1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:12.18.4-2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:6.14.6-1.12.18.4.2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:6.14.5-1.12.18.2.1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:6.14.8-1.12.19.1.1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1.16.1-3.module+el8.0.0+3250+4b7d6d43 | RHSA-2019:1972 | rubygem-bundler | 1.16.1-3.module+el8+2671+ebcc7ee0 | 6.8 | 8.8 | High
Hello, @niteenkole
Releases with updates to 3rd party dependents have to go through another process within Splunk. So it takes more time. Hopefully I can release update soon.
@rockb1017 thanks.
We trying to understand the image/security upgrade process from splunk so that we can define correct security policy from our side.
Can you help us understand with say release like 1.4.5 you still working on 3rd party dependents and need some time.
With 3rd part dependents ready to release it will be like 1.4.6 ?
Most helpful comment
We see similar issue. Having splunk with CVE which has fix in production will be really security issue.
we have latest 1.4.4
fixed_version | name | package_name | package_version | score | score_v3 | severity
-- | -- | -- | -- | -- | -- | --
1:12.18.2-1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:12.16.1-2.module+el8.1.0+6117+b25a342c | RHSA-2020:1293 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 6.8 | 8.8 | High
1:12.19.1-1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1:12.16.1-1.module+el8.1.0+5811+44509afe | RHSA-2020:0598 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 7.5 | 9.8 | High
1:12.18.4-2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | nodejs | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:12.18.2-1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:12.19.1-1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1:12.18.4-2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | nodejs-full-i18n | 1:10.21.0-3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:6.14.6-1.12.18.4.2.module+el8.2.0+8361+192e434e | RHSA-2020:4272 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 4.6 | 7.8 | High
1:6.14.5-1.12.18.2.1.module+el8.2.0+7233+61d664c1 | RHSA-2020:2852 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 9.3 | 8.1 | High
1:6.14.8-1.12.19.1.1.module+el8.3.0+8851+b7b41ca0 | RHSA-2020:5499 | npm | 1:6.14.4-1.10.21.0.3.module+el8.2.0+7071+d2377ea3 | 5 | 7.5 | High
1.16.1-3.module+el8.0.0+3250+4b7d6d43 | RHSA-2019:1972 | rubygem-bundler | 1.16.1-3.module+el8+2671+ebcc7ee0 | 6.8 | 8.8 | High