MEDIUM
The severity is medium because the specific vulnerabilities are unknown but given Chrome's history of critical issues, it poses a risk. Real-world exploitability exists if any zero-day or known vulnerabilities affect this image version.

A headless Chrome container image used in PDF generation service, with the last update from early 2023, could be vulnerable due to unpatched security advisories. This may impact user uploads processed by this service.

Affected Systems
  • Chrome container image
Affected Versions: Versions from early 2023 and earlier
Remediation
  • Update the Chrome container image to the latest version using: docker pull chrome:latest
  • Perform a security scan on updated images before deploying them in production.
Stack Impact

This affects Dockerized services specifically running outdated headless browser containers.

Source →