Forum Discussion

Samuel_St-o's avatar
Samuel_St-o
New Contributor
13 days ago

Vulnerabilities in 1Password CLI Docker image (v2.30.3) – Request for fix timeline

Hello 1Password team,

We are using the official 1password/op:2.30.3 Docker image in a SOC 2–compliant environment, and a recent security scan flagged multiple fixable vulnerabilities in the image, particularly in the 1Password CLI binary and its dependencies.

Vulnerable components (all marked as fixable by our scanner):

  • golang.org/x/crypto v0.27.0 → 1 Critical, 1 High
  • stdlib v1.22.7 → 1 Critical, 3 Medium (likely from Go compiler)
  • golang.org/x/net v0.29.0 → 3 Medium
  • github.com/go-jose/go-jose/v4 v4.0.2 → 1 Medium
  • debian/openssl / debian/glibc / gnutls28 / libtasn1-6 / perl → Multiple Medium
  • debian/gcc-12 → 2 Low (we acknowledge these are non-fixable for now)

Given that all the vulnerabilities above (except gcc-12) are marked as fixable, we would like to ask:

 

  1. Will these vulnerabilities be addressed in the next release of 1Password CLI and its official Docker image?
  2. Is there an estimated release date for the next version?
  3. (Optional) If some of these CVEs are considered not applicable due to usage context, could you provide clarifications for audit purposes?

We greatly appreciate your help. Please let us know if there is a more up-to-date version we should use instead of 1password/op:2.30.3.

Best regards,

2 Replies

  • 1P_Simon's avatar
    1P_Simon
    Icon for 1Password Team rank1Password Team

    Hi Samuel_St-o​ , in our investigations we have not found exploitable vulnerabilities. That said, we've released https://releases.1password.com/developers/cli/#1password-cli-2.31.0 yesterday which does include maintenance updates of dependencies, and you can update as a best practice and to avoid false-positives showing up in your security scanners.

    • 1P_Simon's avatar
      1P_Simon
      Icon for 1Password Team rank1Password Team

      Oh and to answer your question regarding Docker specifically: yes, this release includes updated Docker image: https://hub.docker.com/layers/1password/op/2.31.0/images/sha256-634d922323bf22253bd9f003cc7a44c44584d89b30809d2309b63136114d9919