Sign inSign up

jyoakum/wso2is

By jyoakum

•Updated over 4 years ago

Public version of WSO2 Identity Server docker image without Log4j 2 CVE-2021-44228 vulnerability.

Image
0

1.0K

jyoakum/wso2is repository overview

See the WSO2 docker hub page for details on running and for original images: https://hub.docker.com/r/wso2/wso2is⁠

I used the sample Dockerfile from the WSO2 documentation on mitigating the Log4j2 zero-day vulnerability (CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105) with the exception that I changed it from 5.10.0 to 5.11.0. https://docs.wso2.com/pages/viewpage.action?pageId=180948677⁠

FROM wso2/wso2is:5.11.0
 
USER root
 
RUN \
    apt-get update \
    && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
        zip \
    && rm -rf /var/lib/apt/lists/*
 
USER wso2carbon
 
RUN curl https://raw.githubusercontent.com/wso2/security-tools/master/internal/update-scripts/CVE-2021-44228-mitigation.sh | bash

Once I saved the above Dockerfile locally I ran the following command from the same location as the Dockerfile: $> docker build -t jyoakum/wso2is:5.11.0.log4fixed .

Good luck! If you like WSO2 Identity Server then come to https://wso2.com⁠ and learn about all the other products and how to get the most out of them with a subscription.

Tag summary

Content type

Image

Digest

Size

593.5 MB

Last updated

over 4 years ago

docker pull jyoakum/wso2is:5.11.0.log4fixed