Last scanned:
This image is safe for production use. Although it contains 3 exposed and 14 post-exploit-only findings, all are low severity (maximum 4.67 and 3.51 respectively), and no high-severity issues were identified. The image is from a verified publisher and pinned by digest, reducing supply-chain risk. No known vulnerabilities meet the threshold to require additional attention.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2020-28928 | MEDIUM4.67 | musl 1.1.22-r3 fixed in 1.1.22-r4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2021-23839 | LOW3.7 | libcrypto1.1 1.1.1g-r0 fixed in 1.1.1j-r0 | 3.0% Low-Moderate Risk | Directly Exposed |
| CVE-2021-23839 | LOW3.7 | libssl1.1 1.1.1g-r0 fixed in 1.1.1j-r0 | 3.0% Low-Moderate Risk | Directly Exposed |
| CVE-2021-23840 | LOW3.51 | libcrypto1.1 1.1.1g-r0 fixed in 1.1.1j-r0 | 50.7% Actively Exploited | Post-Exploit |
| CVE-2021-23840 | LOW3.51 | libssl1.1 1.1.1g-r0 fixed in 1.1.1j-r0 | 50.7% Actively Exploited | Post-Exploit |
| CVE-2021-36159 | LOW3.28 | apk-tools 2.10.4-r2 fixed in 2.10.7-r0 | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2021-3450 | LOW3.07 | libcrypto1.1 1.1.1g-r0 fixed in 1.1.1k-r0 | 18.3% High Exploitation Risk | Post-Exploit |
| CVE-2021-3450 | LOW3.07 | libssl1.1 1.1.1g-r0 fixed in 1.1.1k-r0 | 18.3% High Exploitation Risk | Post-Exploit |
| CVE-2021-3449 | LOW2.76 | libcrypto1.1 1.1.1g-r0 fixed in 1.1.1k-r0 | 62.9% Actively Exploited | Post-Exploit |
| CVE-2021-3449 | LOW2.76 | libssl1.1 1.1.1g-r0 fixed in 1.1.1k-r0 | 62.9% Actively Exploited | Post-Exploit |
| CVE-2021-30139 | LOW2.7 | apk-tools 2.10.4-r2 fixed in 2.10.6-r0 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2021-28831 | LOW2.7 | busybox 1.30.1-r3 fixed in 1.30.1-r5 | 2.7% Low-Moderate Risk | Post-Exploit |
| CVE-2021-28831 | LOW2.7 | ssl_client 1.30.1-r3 fixed in 1.30.1-r5 | 2.7% Low-Moderate Risk | Post-Exploit |
| CVE-2020-1971 | LOW2.12 | libcrypto1.1 1.1.1g-r0 fixed in 1.1.1i-r0 | 7.0% Low-Moderate Risk | Post-Exploit |
| CVE-2021-23841 | LOW2.12 | libcrypto1.1 1.1.1g-r0 fixed in 1.1.1j-r0 | 7.5% Low-Moderate Risk | Post-Exploit |
| CVE-2020-1971 | LOW2.12 | libssl1.1 1.1.1g-r0 fixed in 1.1.1i-r0 | 7.0% Low-Moderate Risk | Post-Exploit |
| CVE-2021-23841 | LOW2.12 | libssl1.1 1.1.1g-r0 fixed in 1.1.1j-r0 | 7.5% Low-Moderate Risk | Post-Exploit |
| CVE-2020-28928 | NONE0 | musl-utils 1.1.22-r3 fixed in 1.1.22-r4 | 0.6% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.