Vulnerability remediation - Mailing list pgsql-novice

From Al Wilson
Subject Vulnerability remediation
Date
Msg-id CAH05kiyz7hnbVEEXHc3ow7288OCfK-7jAGQ1JPBnYWRftx9_JA@mail.gmail.com
Whole thread Raw
Responses Re: Vulnerability remediation  (Bzzzz <lazyvirus@gmx.com>)
List pgsql-novice
Does anyone have any insight on this?  Perhaps point to something I can read?
  1. Vulnerability scanner indicates "Postgres default account: postgres/no password"
  2. Scanner  states Proof as "Successfully authenticated to the Postgres service with credentials uid [postgres] pw [realm]
  3. Application owner initially claimed that this was a false positive, but later claimed that it was resolved within the Docker instance
    1. Scanner still showed vulnerability.
  4. Found article that seemed to indicate that using the --env would address the postgres image vs. the Docker.
    1. https://squaredup.com/blog/running-postgres-in-docker/
    2. Scanner still shows vulnerability.
  5. PostGres version is 9.5, if that makes a difference.

pgsql-novice by date:

Previous
From: Ibrahim Shaame
Date:
Subject: Re: reporting tree into separate columns
Next
From: Bzzzz
Date:
Subject: Re: Vulnerability remediation