Public version of WSO2 Identity Server docker image without Log4j 2 CVE-2021-44228 vulnerability.
1.0K
See the WSO2 docker hub page for details on running and for original images: https://hub.docker.com/r/wso2/wso2is
I used the sample Dockerfile from the WSO2 documentation on mitigating the Log4j2 zero-day vulnerability (CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105) with the exception that I changed it from 5.10.0 to 5.11.0. https://docs.wso2.com/pages/viewpage.action?pageId=180948677
FROM wso2/wso2is:5.11.0
USER root
RUN \
apt-get update \
&& DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
zip \
&& rm -rf /var/lib/apt/lists/*
USER wso2carbon
RUN curl https://raw.githubusercontent.com/wso2/security-tools/master/internal/update-scripts/CVE-2021-44228-mitigation.sh | bash
Once I saved the above Dockerfile locally I ran the following command from the same location as the Dockerfile: $> docker build -t jyoakum/wso2is:5.11.0.log4fixed .
Good luck! If you like WSO2 Identity Server then come to https://wso2.com and learn about all the other products and how to get the most out of them with a subscription.
Content type
Image
Digest
Size
593.5 MB
Last updated
over 4 years ago
docker pull jyoakum/wso2is:5.11.0.log4fixed