UNCLASSIFIED - NO CUI

Skip to content

Redis, CVE-2025-49844 (Anchore Team Inquiry)

Hi IB Team,

The current BB (Big Bang) chart for Anchore Enterprise is using a version of Redis affected by this critical vulnerability (CVE-2025-49844).

https://repo1.dso.mil/big-bang/product/packages/anchore-enterprise/-/blob/main/chart/Chart.yaml?ref_type=heads#L54

Are there any plans to update the chart with a patched version (potentially one of the below).

registry1.dso.mil/ironbank/bitnami/redis:8.2.2 registry1.dso.mil/ironbank/opensource/redis/redis8:8.2.2

I'm actually the person on the Anchore side responsible for pushing up the latest versions of Anchore Enterprise to IB and we have a few customers using the IB images who are inquiring about the Redis image in the BB chart.