⚠️ This issue respects the following points: ⚠️
Bug description
Hello,
Trivy detects that nextcloud third party components contain an outdated guzzlehttp/guzzle library that is vulnerable.
I know pull requests are there to update guzzlehttp #32638 & #32636 but it is not clear to me whether they are intended to cover the library used in nextcloud/apps/files_external/3rdparty/
also those pull requests have not been completed yet (not merged).
reference upstream: GHSA-cwmx-hcrq-mhc3
Steps to reproduce
trivy image nextcloud:24
usr/src/nextcloud/3rdparty/composer.lock (composer)
Total: 3 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)
┌───────────────────┬────────────────┬──────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Installed Version │ Fixed Version │ Title │
├───────────────────┼────────────────┼──────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────────┤
│ guzzlehttp/guzzle │ CVE-2022-29248 │ HIGH │ 7.4.1 │ 7.4.3, 6.5.6 │ Cross-domain cookie leakage │
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-29248 │
Expected behavior
clarity on vulnerability status of nextcloud for GHSA-cwmx-hcrq-mhc3
or an update plan for nextcloud to fix the cve.
Installation method
Official Docker image
Operating system
Debian/Ubuntu
PHP engine version
PHP 8.0
Web server
Apache (supported)
Database engine version
MariaDB
Is this bug present after an update or on a fresh install?
Fresh Nextcloud Server install
Are you using the Nextcloud Server Encryption module?
Encryption is Disabled
What user-backends are you using?
Configuration report
List of activated Apps
Nextcloud Signing status
Nextcloud Logs
Additional info
No response
Bug description
Hello,
Trivy detects that nextcloud third party components contain an outdated guzzlehttp/guzzle library that is vulnerable.
I know pull requests are there to update guzzlehttp #32638 & #32636 but it is not clear to me whether they are intended to cover the library used in nextcloud/apps/files_external/3rdparty/
also those pull requests have not been completed yet (not merged).
reference upstream: GHSA-cwmx-hcrq-mhc3
Steps to reproduce
Expected behavior
clarity on vulnerability status of nextcloud for GHSA-cwmx-hcrq-mhc3
or an update plan for nextcloud to fix the cve.
Installation method
Official Docker image
Operating system
Debian/Ubuntu
PHP engine version
PHP 8.0
Web server
Apache (supported)
Database engine version
MariaDB
Is this bug present after an update or on a fresh install?
Fresh Nextcloud Server install
Are you using the Nextcloud Server Encryption module?
Encryption is Disabled
What user-backends are you using?
Configuration report
.List of activated Apps
.Nextcloud Signing status
.Nextcloud Logs
.Additional info
No response