UNCLASSIFIED - NO CUI

Skip to content

chore(findings): aiml/jupyter/jlab-network

Summary

aiml/jupyter/jlab-network has 51 new findings discovered during continuous monitoring.

id source severity package
CVE-2022-44638 Twistlock CVE Medium pixman-0.38.4-2.el8
CVE-2022-2519 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-2963 Twistlock CVE Medium jasper-libs-2.0.14-5.el8
CVE-2022-3970 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-3627 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-3626 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-3599 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-3598 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-3570 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-2953 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-2869 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2022-2867 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2021-3826 Twistlock CVE Low libstdc++-devel-8.5.0-15.el8
CVE-2022-2521 Twistlock CVE Low libtiff-4.0.9-23.el8
CVE-2022-40755 Twistlock CVE Low jasper-libs-2.0.14-5.el8
CVE-2022-3857 Twistlock CVE Low libpng-1.6.34-5.el8
CVE-2022-2868 Twistlock CVE Low libtiff-4.0.9-23.el8
CVE-2022-27943 Twistlock CVE Low gcc-c++-8.5.0-15.el8
CVE-2022-27943 Twistlock CVE Low libstdc++-devel-8.5.0-15.el8
CVE-2022-2520 Twistlock CVE Low libtiff-4.0.9-23.el8
CVE-2020-35538 Twistlock CVE Low libjpeg-turbo-1.5.3-12.el8
CVE-2021-46195 Twistlock CVE Low libstdc++-devel-8.5.0-15.el8
CVE-2019-14250 Twistlock CVE Low libstdc++-devel-8.5.0-15.el8
CVE-2019-14250 Twistlock CVE Low gcc-c++-8.5.0-15.el8
CVE-2018-20657 Twistlock CVE Low gcc-c++-8.5.0-15.el8
CVE-2018-20657 Twistlock CVE Low libstdc++-devel-8.5.0-15.el8
CVE-2022-3554 Anchore CVE Medium libX11-common-1.6.8-5.el8
CVE-2022-3570 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-27943 Anchore CVE Low libstdc++-devel-8.5.0-15.el8
CVE-2020-35538 Anchore CVE Low libjpeg-turbo-1.5.3-12.el8
CVE-2022-3555 Anchore CVE Low libX11-1.6.8-5.el8
CVE-2022-2953 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-2519 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-3627 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-3970 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-2869 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-2521 Anchore CVE Low libtiff-4.0.9-23.el8
CVE-2022-2963 Anchore CVE Medium jasper-libs-2.0.14-5.el8
CVE-2022-3857 Anchore CVE Low libpng-2:1.6.34-5.el8
CVE-2022-3598 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-2868 Anchore CVE Low libtiff-4.0.9-23.el8
CVE-2022-3599 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-27943 Anchore CVE Low gcc-c++-8.5.0-15.el8
CVE-2022-3554 Anchore CVE Medium libX11-1.6.8-5.el8
CVE-2022-40755 Anchore CVE Low jasper-libs-2.0.14-5.el8
CVE-2022-2867 Anchore CVE Medium libtiff-4.0.9-23.el8
CVE-2022-3555 Anchore CVE Low libX11-common-1.6.8-5.el8
CVE-2022-44638 Anchore CVE Medium pixman-0.38.4-2.el8
CVE-2022-2520 Anchore CVE Low libtiff-4.0.9-23.el8
CVE-2022-3597 Twistlock CVE Medium libtiff-4.0.9-23.el8
CVE-2019-7317 Twistlock CVE Low libpng-1.6.34-5.el8

VAT: https://vat.dso.mil/vat/image?imageName=aiml/jupyter/jlab-network&tag=3.5.0&branch=master
More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/aiml/jupyter/jlab-network/-/jobs/13809316

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the ~"Approval" label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications
  • Send approval request to Authorizing Official
  • Close issue after approval from Authorizing Official

Note: If the above approval process is rejected for any reason, the Approval label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Approval label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by Ghost User
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information