如何修复Debian镜像安装Python3.10/pip时的CVE-2015-20107漏洞
解决CVE-2015-20107告警的办法
这个CVE对应的是debian系统中shadow工具集(包含useradd、usermod等命令)的漏洞,debian stable官方仓库已经提供了修复后的版本,你的镜像触发告警是因为基础镜像里的shadow包未更新到补丁版本,试试以下几种解决方式:
全量升级系统包后安装:在安装Python前先执行系统升级,确保所有包都是最新补丁版本
FROM debian:stable RUN apt-get update && apt-get upgrade -y && \ apt-get install -y --no-install-recommends python3.10 python3-pip && \ apt-get clean && rm -rf /var/lib/apt/lists/*单独升级
shadow包:如果不想全量升级系统,只单独安装最新版的shadow包即可覆盖旧版本FROM debian:stable RUN apt-get update && \ apt-get install -y --no-install-recommends shadow python3.10 python3-pip && \ apt-get clean && rm -rf /var/lib/apt/lists/*切换到
slim镜像(可选):debian:stable-slim镜像更精简,同样可以通过上述两种方式确保shadow包是最新版,能进一步减小镜像体积
内容的提问来源于stack exchange,提问作者addy
相关产品推荐
相关产品推荐

