Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ignore CVE-2023-50495 #2596

Merged
merged 1 commit into from
Dec 19, 2023
Merged

Ignore CVE-2023-50495 #2596

merged 1 commit into from
Dec 19, 2023

Conversation

dannymidnight
Copy link
Contributor

It concerns ncurses containing "a segmentation fault via the component
_nc_wrap_entry()". We feel safe in ignoring this for a few reasons:

1. We do not run ncurses in our Docker images, be that in CI/CD or in
   Production, because it's an interactive terminal (i.e. no practical
   use case).
2. In the off chance someone does exec into the container to then try to
   leverage this as a vulnerability, they'll already have the power to
   install any malicious software they want. I.e. if they can get into
   the container with malicious intent, we've got bigger problems than
   an ncurses segfault.
@buildkite-docs-bot
Copy link
Contributor

Preview URL: https://2596--bk-docs-preview.netlify.app

@dannymidnight dannymidnight merged commit 64c6b10 into main Dec 19, 2023
1 of 3 checks passed
@dannymidnight dannymidnight deleted the ignore-CVE-2023-50495 branch December 19, 2023 22:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants