diff --git a/Dockerfile b/Dockerfile index f452de10c..2b2784009 100644 --- a/Dockerfile +++ b/Dockerfile @@ -31,8 +31,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache diff --git a/Dockerfile-amd64 b/Dockerfile-amd64 index 68077884a..669a180f5 100644 --- a/Dockerfile-amd64 +++ b/Dockerfile-amd64 @@ -31,8 +31,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache diff --git a/Dockerfile-arm32v7 b/Dockerfile-arm32v7 index fae988a33..85d601cec 100644 --- a/Dockerfile-arm32v7 +++ b/Dockerfile-arm32v7 @@ -38,8 +38,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache diff --git a/Dockerfile-arm64v8 b/Dockerfile-arm64v8 index 2c9a7572b..f976bc577 100644 --- a/Dockerfile-arm64v8 +++ b/Dockerfile-arm64v8 @@ -38,8 +38,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache diff --git a/Dockerfile-i386 b/Dockerfile-i386 index b3f24fd70..23e92942d 100644 --- a/Dockerfile-i386 +++ b/Dockerfile-i386 @@ -31,8 +31,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache