Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
Samuel_St-o
5 months agoNew Contributor
Vulnerabilities in 1Password CLI Docker image (v2.30.3) – Request for fix timeline
Hello 1Password team,
We are using the official 1password/op:2.30.3 Docker image in a SOC 2–compliant environment, and a recent security scan flagged multiple fixable vulnerabilities in the image, particularly in the 1Password CLI binary and its dependencies.
Vulnerable components (all marked as fixable by our scanner):
- golang.org/x/crypto v0.27.0 → 1 Critical, 1 High
- stdlib v1.22.7 → 1 Critical, 3 Medium (likely from Go compiler)
- golang.org/x/net v0.29.0 → 3 Medium
- github.com/go-jose/go-jose/v4 v4.0.2 → 1 Medium
- debian/openssl / debian/glibc / gnutls28 / libtasn1-6 / perl → Multiple Medium
- debian/gcc-12 → 2 Low (we acknowledge these are non-fixable for now)
Given that all the vulnerabilities above (except gcc-12) are marked as fixable, we would like to ask:
- Will these vulnerabilities be addressed in the next release of 1Password CLI and its official Docker image?
- Is there an estimated release date for the next version?
- (Optional) If some of these CVEs are considered not applicable due to usage context, could you provide clarifications for audit purposes?
We greatly appreciate your help. Please let us know if there is a more up-to-date version we should use instead of 1password/op:2.30.3.
Best regards,
2 Replies
- 1P_Simon
1Password Team
Hi Samuel_St-o , in our investigations we have not found exploitable vulnerabilities. That said, we've released https://releases.1password.com/developers/cli/#1password-cli-2.31.0 yesterday which does include maintenance updates of dependencies, and you can update as a best practice and to avoid false-positives showing up in your security scanners.
- 1P_Simon
1Password Team
Oh and to answer your question regarding Docker specifically: yes, this release includes updated Docker image: https://hub.docker.com/layers/1password/op/2.31.0/images/sha256-634d922323bf22253bd9f003cc7a44c44584d89b30809d2309b63136114d9919