UNCLASSIFIED - NO CUI

chore(findings): aperio-global/russel/unstructured-data-processing

Summary

aperio-global/russel/unstructured-data-processing has 572 new findings discovered during continuous monitoring.

id source severity package
902d1de5d452649b124ecd1f9117c179 Anchore Compliance Critical
499c3158d825decd381e09f2ecd21556 Anchore Compliance Critical
GHSA-q4mp-jvh2-76fj Anchore CVE High Pillow-9.2.0
GHSA-74m5-2c7w-9w3x Anchore CVE Medium starlette-0.20.4
GHSA-43fp-rhv2-5gv8 Anchore CVE Medium certifi-2022.9.24
GHSA-3qj8-93xh-pwh2 Anchore CVE High starlette-0.20.4
CVE-2023-27043 Anchore CVE Medium python-3.10.10
GHSA-v5gw-mw7f-84px Anchore CVE Low starlette-0.20.4
CVE-2023-28321 Anchore CVE Medium libcurl-7.61.1-25.el8_7.3
CVE-2023-28321 Anchore CVE Medium curl-7.61.1-25.el8_7.3
GHSA-282v-666c-3fvg Anchore CVE Medium transformers-4.24.0
GHSA-j8r2-6x86-q33q Anchore CVE Medium requests-2.28.1
CVE-2023-32681 Anchore CVE Medium python3-requests-2.20.0-2.1.el8_1
CVE-2023-2603 Anchore CVE Medium libcap-2.48-4.el8
CVE-2023-2602 Anchore CVE Low libcap-2.48-4.el8
CVE-2023-34969 Anchore CVE Medium dbus-common-1:1.12.8-23.el8_7.1
CVE-2023-34969 Anchore CVE Medium dbus-daemon-1:1.12.8-23.el8_7.1
CVE-2023-34969 Anchore CVE Medium dbus-1:1.12.8-23.el8_7.1
CVE-2023-34969 Anchore CVE Medium dbus-libs-1:1.12.8-23.el8_7.1
CVE-2023-34969 Anchore CVE Medium dbus-tools-1:1.12.8-23.el8_7.1
GHSA-4vvm-4w3v-6mr8 Anchore CVE Medium PyPDF2-2.10.2
CVE-2023-36632 Anchore CVE High python-3.10.10
GHSA-xqr8-7jwr-rhp7 Anchore CVE High certifi-2022.9.24
CVE-2023-28322 Anchore CVE Low curl-7.61.1-25.el8_7.3
CVE-2023-28322 Anchore CVE Low libcurl-7.61.1-25.el8_7.3
CVE-2023-3446 Anchore CVE Low openssl-libs-1:1.1.1k-9.el8_7
CVE-2023-3899 Anchore CVE High python3-cloud-what-1.28.32-1.el8
CVE-2023-3899 Anchore CVE High python3-subscription-manager-rhsm-1.28.32-1.el8
CVE-2023-3899 Anchore CVE High python3-syspurpose-1.28.32-1.el8
CVE-2023-3899 Anchore CVE High subscription-manager-1.28.32-1.el8
CVE-2023-3899 Anchore CVE High subscription-manager-rhsm-certificates-1.28.32-1.el8
CVE-2023-3899 Anchore CVE High dnf-plugin-subscription-manager-1.28.32-1.el8
CVE-2022-47007 Anchore CVE Low gdb-gdbserver-8.2-19.el8
CVE-2022-47010 Anchore CVE Low gdb-gdbserver-8.2-19.el8
CVE-2022-47011 Anchore CVE Low gdb-gdbserver-8.2-19.el8
CVE-2023-40217 Anchore CVE High python3-libs-3.6.8-48.el8_7.1
CVE-2023-40217 Anchore CVE Medium python-3.10.10
CVE-2023-39615 Anchore CVE Medium python3-libxml2-2.9.7-15.el8_7.1
CVE-2023-4641 Anchore CVE Low shadow-utils-2:4.6-17.el8
CVE-2023-40217 Anchore CVE High platform-python-3.6.8-48.el8_7.1
CVE-2023-39615 Anchore CVE Medium libxml2-2.9.7-15.el8_7.1
CVE-2023-4813 Anchore CVE Medium glibc-2.28-211.el8
CVE-2023-4813 Anchore CVE Medium glibc-common-2.28-211.el8
CVE-2023-4527 Anchore CVE Medium glibc-minimal-langpack-2.28-211.el8
CVE-2023-4527 Anchore CVE Medium glibc-2.28-211.el8
CVE-2023-4806 Anchore CVE Medium glibc-common-2.28-211.el8
CVE-2023-4806 Anchore CVE Medium glibc-minimal-langpack-2.28-211.el8
CVE-2023-4527 Anchore CVE Medium glibc-common-2.28-211.el8
CVE-2023-4813 Anchore CVE Medium glibc-minimal-langpack-2.28-211.el8
CVE-2023-4806 Anchore CVE Medium glibc-2.28-211.el8
GHSA-v845-jxx5-vc9f Anchore CVE Medium urllib3-1.26.12
GHSA-j7hp-h8jx-5ppr Anchore CVE High Pillow-9.2.0
CVE-2023-4911 Anchore CVE High glibc-minimal-langpack-2.28-211.el8
CVE-2023-4911 Anchore CVE High glibc-2.28-211.el8
CVE-2023-4911 Anchore CVE High glibc-common-2.28-211.el8
GHSA-56pw-mpj4-fxww Anchore CVE High Pillow-9.2.0
CVE-2023-43804 Anchore CVE Medium python3-urllib3-1.24.2-5.el8
CVE-2023-5388 Anchore CVE Medium nss-softokn-3.79.0-11.el8_7
CVE-2023-5388 Anchore CVE Medium nss-sysinit-3.79.0-11.el8_7
CVE-2023-38546 Anchore CVE Low libcurl-7.61.1-25.el8_7.3
CVE-2023-5388 Anchore CVE Medium nss-util-3.79.0-11.el8_7
CVE-2023-38546 Anchore CVE Low curl-7.61.1-25.el8_7.3
CVE-2023-44487 Anchore CVE High libnghttp2-1.33.0-3.el8_2.1
CVE-2023-5388 Anchore CVE Medium nss-3.79.0-11.el8_7
CVE-2023-5388 Anchore CVE Medium nss-softokn-freebl-3.79.0-11.el8_7
GHSA-g4mx-q9vg-27p4 Anchore CVE Medium urllib3-1.26.12
GHSA-mq26-g339-26xf Anchore CVE Medium pip-23.0.1
GHSA-8ghj-p4vj-mr35 Anchore CVE High Pillow-9.2.0
CVE-2007-4559 Anchore CVE Medium python3-pip-wheel-9.0.3-22.el8
CVE-2023-5678 Anchore CVE Low openssl-libs-1:1.1.1k-9.el8_7
CVE-2023-37920 Anchore CVE Low ca-certificates-2022.2.54-80.2.el8_6
CVE-2022-48560 Anchore CVE Medium platform-python-3.6.8-48.el8_7.1
CVE-2022-48560 Anchore CVE Medium python3-libs-3.6.8-48.el8_7.1
CVE-2022-48564 Anchore CVE Medium python3-libs-3.6.8-48.el8_7.1
CVE-2022-48564 Anchore CVE Medium platform-python-3.6.8-48.el8_7.1
CVE-2023-45803 Anchore CVE Medium python3-urllib3-1.24.2-5.el8
CVE-2022-42898 Anchore CVE High krb5-libs-1.18.2-22.el8_7
CVE-2023-5981 Anchore CVE Medium gnutls-3.6.16-6.el8_7
CVE-2023-46218 Anchore CVE Medium libcurl-7.61.1-25.el8_7.3
CVE-2023-46218 Anchore CVE Medium curl-7.61.1-25.el8_7.3
CVE-2023-3817 Anchore CVE Low openssl-libs-1:1.1.1k-9.el8_7
CVE-2023-7008 Anchore CVE Medium systemd-pam-239-68.el8_7.4
CVE-2023-7008 Anchore CVE Medium systemd-libs-239-68.el8_7.4
CVE-2023-7008 Anchore CVE Medium systemd-239-68.el8_7.4
GHSA-v68g-wm8c-6x7j Anchore CVE High transformers-4.24.0
GHSA-3863-2447-669p Anchore CVE Critical transformers-4.24.0
CVE-2023-7104 Anchore CVE Medium sqlite-libs-3.26.0-17.el8_7
CVE-2023-6135 Anchore CVE Medium nss-util-3.79.0-11.el8_7
CVE-2023-6135 Anchore CVE Medium nss-sysinit-3.79.0-11.el8_7
CVE-2023-6135 Anchore CVE Medium nss-softokn-freebl-3.79.0-11.el8_7
CVE-2023-6135 Anchore CVE Medium nss-3.79.0-11.el8_7
CVE-2023-6135 Anchore CVE Medium nss-softokn-3.79.0-11.el8_7
GHSA-h5c8-rqwp-cp95 Anchore CVE Medium Jinja2-3.1.2
CVE-2023-5455 Anchore CVE Medium krb5-libs-1.18.2-22.el8_7
CVE-2021-43618 Anchore CVE Medium gmp-1:6.1.2-10.el8
CVE-2024-0553 Anchore CVE Medium gnutls-3.6.16-6.el8_7
CVE-2024-22365 Anchore CVE Medium pam-1.3.1-22.el8
CVE-2023-32665 Anchore CVE Low glib2-2.56.4-159.el8
CVE-2023-29499 Anchore CVE Low glib2-2.56.4-159.el8
CVE-2023-32611 Anchore CVE Low glib2-2.56.4-159.el8
GHSA-3f63-hfp8-52jq Anchore CVE High Pillow-9.2.0
CVE-2023-52425 Anchore CVE Medium expat-2.2.5-10.el8_7.1
CVE-2024-25062 Anchore CVE Medium libxml2-2.9.7-15.el8_7.1
CVE-2024-25062 Anchore CVE Medium python3-libxml2-2.9.7-15.el8_7.1
GHSA-2jv5-9r88-3w3p Anchore CVE High fastapi-0.86.0
GHSA-2jv5-9r88-3w3p Anchore CVE High starlette-0.20.4
GHSA-pwr2-4v36-6qpr Anchore CVE High orjson-3.8.1
CVE-2020-24736 OSCAP Compliance Medium
CVE-2023-1667 OSCAP Compliance Medium
CVE-2023-2283 OSCAP Compliance Medium
CVE-2023-26604 OSCAP Compliance Medium
CVE-2023-24329 OSCAP Compliance Medium
CVE-2023-27535 OSCAP Compliance Medium
CVE-2022-36227 OSCAP Compliance Medium
CVE-2022-35252 OSCAP Compliance Medium
CVE-2022-43552 OSCAP Compliance Medium
CVE-2023-34969 OSCAP Compliance Medium
CVE-2023-28484 OSCAP Compliance Medium
CVE-2023-29469 OSCAP Compliance Medium
CVE-2023-2602 OSCAP Compliance Medium
CVE-2023-2603 OSCAP Compliance Medium
CVE-2023-27536 OSCAP Compliance Medium
CVE-2023-28321 OSCAP Compliance Medium
CVE-2023-32681 OSCAP Compliance Medium
CVE-2023-3899 OSCAP Compliance Medium
CVE-2023-30630 OSCAP Compliance Medium
CVE-2023-29491 OSCAP Compliance Medium
CVE-2023-4527 OSCAP Compliance Medium
CVE-2023-4806 OSCAP Compliance Medium
CVE-2023-4813 OSCAP Compliance Medium
CVE-2023-4911 OSCAP Compliance Medium
CVE-2023-44487 OSCAP Compliance Medium
CVE-2023-40217 OSCAP Compliance Medium
CVE-2007-4559 OSCAP Compliance Medium
CVE-2023-22745 OSCAP Compliance Medium
CVE-2023-4641 OSCAP Compliance Medium
CVE-2022-42898 OSCAP Compliance Medium
CVE-2023-3446 OSCAP Compliance Medium
CVE-2023-3817 OSCAP Compliance Medium
CVE-2023-5678 OSCAP Compliance Medium
CCE-86931-3 OSCAP Compliance Medium
CCE-86916-4 OSCAP Compliance Medium
CCE-85902-5 OSCAP Compliance High
CCE-85897-7 OSCAP Compliance Medium
CCE-85870-4 OSCAP Compliance Medium
CCE-85899-3 OSCAP Compliance Medium
CVE-2023-5981 OSCAP Compliance Medium
CVE-2023-39615 OSCAP Compliance Medium
CVE-2023-43804 OSCAP Compliance Medium
CVE-2023-45803 OSCAP Compliance Medium
CVE-2022-48560 OSCAP Compliance Medium
CVE-2022-48564 OSCAP Compliance Medium
CVE-2023-5388 OSCAP Compliance Medium
CVE-2023-27043 OSCAP Compliance Medium
CVE-2023-7104 OSCAP Compliance Medium
CVE-2023-48795 OSCAP Compliance Medium
CVE-2024-0553 OSCAP Compliance Medium
CVE-2021-35937 OSCAP Compliance Medium
CVE-2021-35938 OSCAP Compliance Medium
CVE-2021-35939 OSCAP Compliance Medium
CVE-2023-6135 OSCAP Compliance Medium
CCE-86261-5 OSCAP Compliance Medium
CCE-80675-2 OSCAP Compliance Medium
CCE-85964-5 OSCAP Compliance Medium
CCE-82891-3 OSCAP Compliance Medium
CCE-84220-3 OSCAP Compliance Low
CCE-83733-6 OSCAP Compliance Low
CCE-80763-6 OSCAP Compliance Medium
CCE-83918-3 OSCAP Compliance Medium
CCE-82988-7 OSCAP Compliance Low
CCE-82840-0 OSCAP Compliance Low
CCE-84300-3 OSCAP Compliance Medium
CCE-86266-4 OSCAP Compliance Medium
CCE-80785-9 OSCAP Compliance High
CCE-82155-3 OSCAP Compliance High
CCE-80942-6 OSCAP Compliance High
CCE-80789-1 OSCAP Compliance High
CCE-86478-5 OSCAP Compliance Medium
CCE-84029-8 OSCAP Compliance Medium
CCE-82028-2 OSCAP Compliance Medium
CCE-80832-9 OSCAP Compliance Medium
CCE-82059-7 OSCAP Compliance Medium
CCE-81031-7 OSCAP Compliance Low
CCE-82005-0 OSCAP Compliance Low
CCE-80834-5 OSCAP Compliance Medium
CCE-82297-3 OSCAP Compliance Low
CCE-80835-2 OSCAP Compliance Medium
CCE-86960-2 OSCAP Compliance Medium
CCE-90784-0 OSCAP Compliance Medium
CCE-80837-8 OSCAP Compliance Medium
CCE-80838-6 OSCAP Compliance Medium
CCE-80839-4 OSCAP Compliance Medium
CCE-80844-4 OSCAP Compliance Medium
CCE-81043-2 OSCAP Compliance Medium
CCE-82191-8 OSCAP Compliance Medium
CCE-82998-6 OSCAP Compliance Medium
CCE-87036-0 OSCAP Compliance Medium
CCE-86260-7 OSCAP Compliance Medium
CCE-80846-9 OSCAP Compliance Medium
CCE-83303-8 OSCAP Compliance Medium
CCE-82976-2 OSCAP Compliance Low
CCE-85983-5 OSCAP Compliance Medium
CCE-82859-0 OSCAP Compliance Medium
CCE-80847-7 OSCAP Compliance Medium
CCE-80644-8 OSCAP Compliance Medium
CCE-81044-0 OSCAP Compliance Low
CCE-80851-9 OSCAP Compliance Low
CCE-80852-7 OSCAP Compliance Low
CCE-80853-5 OSCAP Compliance Low
CCE-80854-3 OSCAP Compliance Low
CCE-82730-3 OSCAP Compliance Medium
CCE-80859-2 OSCAP Compliance Medium
CCE-86339-9 OSCAP Compliance Medium
CCE-86098-1 OSCAP Compliance Medium
CCE-85992-6 OSCAP Compliance Medium
CCE-83426-7 OSCAP Compliance Medium
CCE-80863-4 OSCAP Compliance Medium
CCE-80868-3 OSCAP Compliance Medium
CCE-80869-1 OSCAP Compliance High
CCE-86353-0 OSCAP Compliance Medium
CCE-82249-4 OSCAP Compliance Medium
CCE-80886-5 OSCAP Compliance Medium
CCE-82426-8 OSCAP Compliance Medium
CCE-82853-3 OSCAP Compliance Medium
CCE-90781-6 OSCAP Compliance Medium
CCE-82462-3 OSCAP Compliance Low
CCE-84027-2 OSCAP Compliance High
CCE-81027-5 OSCAP Compliance Medium
CCE-81030-9 OSCAP Compliance Medium
CCE-82215-5 OSCAP Compliance Medium
CCE-80913-7 OSCAP Compliance Low
CCE-80952-5 OSCAP Compliance Medium
CCE-80915-2 OSCAP Compliance Medium
CCE-81054-9 OSCAP Compliance Low
CCE-80916-0 OSCAP Compliance Medium
CCE-82974-7 OSCAP Compliance Medium
CCE-80953-3 OSCAP Compliance Medium
CCE-82934-1 OSCAP Compliance Medium
CCE-80917-8 OSCAP Compliance Medium
CCE-81011-9 OSCAP Compliance Medium
CCE-86220-1 OSCAP Compliance Medium
CCE-81021-8 OSCAP Compliance Medium
CCE-80918-6 OSCAP Compliance Medium
CCE-80919-4 OSCAP Compliance Medium
CCE-80920-2 OSCAP Compliance Medium
CCE-80921-0 OSCAP Compliance Medium
CCE-80922-8 OSCAP Compliance Medium
CCE-81006-9 OSCAP Compliance Medium
CCE-81009-3 OSCAP Compliance Medium
CCE-81013-5 OSCAP Compliance Medium
CCE-82863-2 OSCAP Compliance Medium
CCE-81007-7 OSCAP Compliance Medium
CCE-81010-1 OSCAP Compliance Medium
CCE-81015-0 OSCAP Compliance Medium
CCE-82211-4 OSCAP Compliance Medium
CCE-83774-0 OSCAP Compliance Medium
CVE-2023-6730 Twistlock CVE Critical transformers-4.24.0
CVE-2023-4863 Twistlock CVE High pillow-9.2.0
CVE-2023-40217 Twistlock CVE Critical platform-python-3.6.8-48.el8_7.1
CVE-2023-40217 Twistlock CVE Critical python3-libs-3.6.8-48.el8_7.1
CVE-2023-7018 Twistlock CVE High transformers-4.24.0
CVE-2023-4911 Twistlock CVE Critical glibc-minimal-langpack-2.28-211.el8
CVE-2023-4911 Twistlock CVE Critical glibc-common-2.28-211.el8
CVE-2023-4911 Twistlock CVE Critical glibc-2.28-211.el8
CVE-2023-3899 Twistlock CVE Critical python3-syspurpose-1.28.32-1.el8
CVE-2023-3899 Twistlock CVE Critical python3-subscription-manager-rhsm-1.28.32-1.el8
CVE-2023-3899 Twistlock CVE Critical python3-cloud-what-1.28.32-1.el8
CVE-2023-3899 Twistlock CVE Critical dnf-plugin-subscription-manager-1.28.32-1.el8
CVE-2023-3899 Twistlock CVE Critical subscription-manager-rhsm-certificates-1.28.32-1.el8
CVE-2023-3899 Twistlock CVE Critical subscription-manager-1.28.32-1.el8
CVE-2024-27454 Twistlock CVE High orjson-3.8.1
CVE-2024-24762 Twistlock CVE High python-multipart-0.0.6
CVE-2024-24762 Twistlock CVE High starlette-0.20.4
CVE-2024-24762 Twistlock CVE High fastapi-0.86.0
CVE-2023-44487 Twistlock CVE Critical libnghttp2-1.33.0-3.el8_2.1
GHSA-56pw-mpj4-fxww Twistlock CVE High pillow-9.2.0
CVE-2023-29491 Twistlock CVE Medium ncurses-libs-6.1-9.20180224.el8
CVE-2023-29491 Twistlock CVE Medium ncurses-base-6.1-9.20180224.el8
CVE-2023-2603 Twistlock CVE Medium libcap-2.48-4.el8
CVE-2024-25062 Twistlock CVE Medium python3-libxml2-2.9.7-15.el8_7.1
CVE-2024-25062 Twistlock CVE Medium libxml2-2.9.7-15.el8_7.1
CVE-2024-0553 Twistlock CVE Medium gnutls-3.6.16-6.el8_7
CVE-2023-52425 Twistlock CVE Medium expat-2.2.5-10.el8_7.1
CVE-2022-48560 Twistlock CVE Medium python3-libs-3.6.8-48.el8_7.1
CVE-2022-48560 Twistlock CVE Medium platform-python-3.6.8-48.el8_7.1
CVE-2023-7104 Twistlock CVE Medium sqlite-libs-3.26.0-17.el8_7
CVE-2023-30630 Twistlock CVE Medium dmidecode-3.3-4.el8
CVE-2022-23491 Twistlock CVE Medium certifi-2022.9.24
CVE-2023-5455 Twistlock CVE Medium krb5-libs-1.18.2-22.el8_7
CVE-2023-5388 Twistlock CVE Medium nss-sysinit-3.79.0-11.el8_7
CVE-2023-5388 Twistlock CVE Medium nss-softokn-3.79.0-11.el8_7
CVE-2023-5388 Twistlock CVE Medium nss-3.79.0-11.el8_7
CVE-2023-5388 Twistlock CVE Medium nss-util-3.79.0-11.el8_7
CVE-2023-5388 Twistlock CVE Medium nss-softokn-freebl-3.79.0-11.el8_7
CVE-2023-4527 Twistlock CVE Medium glibc-common-2.28-211.el8
CVE-2023-4527 Twistlock CVE Medium glibc-minimal-langpack-2.28-211.el8
CVE-2023-4527 Twistlock CVE Medium glibc-2.28-211.el8
CVE-2022-48564 Twistlock CVE Medium platform-python-3.6.8-48.el8_7.1
CVE-2022-48564 Twistlock CVE Medium python3-libs-3.6.8-48.el8_7.1
CVE-2023-36464 Twistlock CVE Medium pypdf2-2.10.2
CVE-2023-34969 Twistlock CVE Medium dbus-daemon-1.12.8-23.el8_7.1
CVE-2023-34969 Twistlock CVE Medium dbus-common-1.12.8-23.el8_7.1
CVE-2023-34969 Twistlock CVE Medium dbus-tools-1.12.8-23.el8_7.1
CVE-2023-34969 Twistlock CVE Medium dbus-libs-1.12.8-23.el8_7.1
CVE-2023-34969 Twistlock CVE Medium dbus-1.12.8-23.el8_7.1
CVE-2020-24736 Twistlock CVE Medium sqlite-libs-3.26.0-17.el8_7
CVE-2023-32681 Twistlock CVE Medium python3-requests-2.20.0-2.1.el8_1
CVE-2023-7008 Twistlock CVE Medium systemd-239-68.el8_7.4
CVE-2023-7008 Twistlock CVE Medium systemd-pam-239-68.el8_7.4
CVE-2023-7008 Twistlock CVE Medium systemd-libs-239-68.el8_7.4
CVE-2023-5981 Twistlock CVE Medium gnutls-3.6.16-6.el8_7
CVE-2023-48795 Twistlock CVE Medium libssh-0.9.6-3.el8
CVE-2023-48795 Twistlock CVE Medium libssh-config-0.9.6-3.el8
CVE-2023-4813 Twistlock CVE Medium glibc-2.28-211.el8
CVE-2023-4813 Twistlock CVE Medium glibc-minimal-langpack-2.28-211.el8
CVE-2023-4813 Twistlock CVE Medium glibc-common-2.28-211.el8
CVE-2023-4806 Twistlock CVE Medium glibc-common-2.28-211.el8
CVE-2023-4806 Twistlock CVE Medium glibc-minimal-langpack-2.28-211.el8
CVE-2023-4806 Twistlock CVE Medium glibc-2.28-211.el8
CVE-2023-43804 Twistlock CVE Medium python3-urllib3-1.24.2-5.el8
CVE-2023-28321 Twistlock CVE Medium libcurl-7.61.1-25.el8_7.3
CVE-2023-28321 Twistlock CVE Medium curl-7.61.1-25.el8_7.3
CVE-2024-22365 Twistlock CVE Medium pam-1.3.1-22.el8
CVE-2023-52426 Twistlock CVE Medium expat-2.2.5-10.el8_7.1
CVE-2023-46218 Twistlock CVE Medium curl-7.61.1-25.el8_7.3
CVE-2023-46218 Twistlock CVE Medium libcurl-7.61.1-25.el8_7.3
CVE-2024-28834 Anchore CVE Medium gnutls-3.6.16-6.el8_7
CVE-2024-2398 Anchore CVE Medium curl-7.61.1-25.el8_7.3
CVE-2024-26458 Anchore CVE Low krb5-libs-1.18.2-22.el8_7
CVE-2024-2398 Anchore CVE Medium libcurl-7.61.1-25.el8_7.3
CVE-2023-6918 Anchore CVE Low libssh-config-0.9.6-3.el8
CVE-2023-48795 Anchore CVE Medium libssh-0.9.6-3.el8
CVE-2023-6918 Anchore CVE Low libssh-0.9.6-3.el8
CVE-2023-6004 Anchore CVE Low libssh-0.9.6-3.el8
CVE-2023-6004 Anchore CVE Low libssh-config-0.9.6-3.el8
CVE-2024-2236 Anchore CVE Medium libgcrypt-1.8.5-7.el8_6
CVE-2023-48795 Anchore CVE Medium libssh-config-0.9.6-3.el8
GHSA-44wm-f244-xhp3 Anchore CVE Medium Pillow-9.2.0
CVE-2024-28182 Anchore CVE Medium libnghttp2-1.33.0-3.el8_2.1
CVE-2024-3205 Anchore CVE Medium libyaml-0.1.7-5.el8
CVE-2024-2511 Anchore CVE Low openssl-libs-1:1.1.1k-9.el8_7
CVE-2024-26461 Anchore CVE Low krb5-libs-1.18.2-22.el8_7
GHSA-37q5-v5qm-c9v8 Anchore CVE Low transformers-4.24.0
CVE-2020-17049 Anchore CVE Medium krb5-libs-1.18.2-22.el8_7
GHSA-jjg7-2v4v-x38h Anchore CVE Medium idna-3.4
GHSA-w3h3-4rj7-4ph4 Anchore CVE High gunicorn-20.1.0
CVE-2024-2961 Anchore CVE High glibc-minimal-langpack-2.28-211.el8
CVE-2024-2961 Anchore CVE High glibc-2.28-211.el8
CVE-2024-2961 Anchore CVE High glibc-common-2.28-211.el8
GHSA-mr82-8j83-vxmv Anchore CVE Medium pydantic-1.10.2
CVE-2023-2953 Anchore CVE Low openldap-2.4.46-18.el8
CVE-2023-6597 Anchore CVE High platform-python-3.6.8-48.el8_7.1
CVE-2024-0450 Anchore CVE Medium platform-python-3.6.8-48.el8_7.1
CVE-2024-0450 Anchore CVE Medium python3-libs-3.6.8-48.el8_7.1
CVE-2023-6597 Anchore CVE High python3-libs-3.6.8-48.el8_7.1
CVE-2021-3997 Anchore CVE Medium systemd-pam-239-68.el8_7.4
CVE-2020-19188 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2020-35512 Anchore CVE Low dbus-libs-1:1.12.8-23.el8_7.1
CVE-2021-33294 Anchore CVE Low elfutils-libelf-0.187-4.el8
CVE-2022-41409 Anchore CVE Low pcre2-10.32-3.el8_6
CVE-2018-20839 Anchore CVE Medium systemd-pam-239-68.el8_7.4
CVE-2021-20193 Anchore CVE Medium tar-2:1.30-6.el8_7.1
CVE-2020-19189 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2018-19211 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2019-1010022 Anchore CVE Critical glibc-minimal-langpack-2.28-211.el8
CVE-2020-12413 Anchore CVE Low nss-sysinit-3.79.0-11.el8_7
CVE-2022-0235 Anchore CVE Medium python3-cloud-what-1.28.32-1.el8
CVE-2020-19187 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2021-24032 Anchore CVE Low libzstd-1.4.4-1.el8
CVE-2023-45322 Anchore CVE Low python3-libxml2-2.9.7-15.el8_7.1
CVE-2024-3651 Anchore CVE Medium python3-idna-2.5-5.el8
CVE-2022-27943 Anchore CVE Low libgcc-8.5.0-16.el8_7
CVE-2018-20657 Anchore CVE Low libstdc++-8.5.0-16.el8_7
CVE-2020-12413 Anchore CVE Low nss-util-3.79.0-11.el8_7
CVE-2019-9674 Anchore CVE Low platform-python-3.6.8-48.el8_7.1
CVE-2019-14250 Anchore CVE Low libstdc++-8.5.0-16.el8_7
GHSA-2jv5-9r88-3w3p Anchore CVE High python-multipart-0.0.6
CVE-2020-35512 Anchore CVE Low dbus-daemon-1:1.12.8-23.el8_7.1
CVE-2019-14250 Anchore CVE Low libgcc-8.5.0-16.el8_7
CVE-2019-9937 Anchore CVE Low sqlite-libs-3.26.0-17.el8_7
CVE-2019-9923 Anchore CVE Low tar-2:1.30-6.el8_7.1
CVE-2020-35512 Anchore CVE Low dbus-tools-1:1.12.8-23.el8_7.1
CVE-2020-19185 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2024-25260 Anchore CVE Low elfutils-libs-0.187-4.el8
CVE-2018-20839 Anchore CVE Medium systemd-239-68.el8_7.4
CVE-2020-12413 Anchore CVE Low nss-softokn-3.79.0-11.el8_7
CVE-2021-33294 Anchore CVE Low elfutils-libs-0.187-4.el8
CVE-2019-9936 Anchore CVE Low sqlite-libs-3.26.0-17.el8_7
CVE-2020-35512 Anchore CVE Low dbus-1:1.12.8-23.el8_7.1
CVE-2022-0235 Anchore CVE Medium dnf-plugin-subscription-manager-1.28.32-1.el8
CVE-2022-3219 Anchore CVE Low gnupg2-2.2.20-3.el8_6
CVE-2019-12900 Anchore CVE Low bzip2-libs-1.0.6-26.el8
CVE-2024-0727 Anchore CVE Low openssl-libs-1:1.1.1k-9.el8_7
CVE-2023-2650 Anchore CVE Medium openssl-libs-1:1.1.1k-9.el8_7
CVE-2023-27534 Anchore CVE Low curl-7.61.1-25.el8_7.3
CVE-2019-1010022 Anchore CVE Critical glibc-2.28-211.el8
CVE-2021-3997 Anchore CVE Medium systemd-239-68.el8_7.4
CVE-2019-8906 Anchore CVE Low file-libs-5.33-21.el8
CVE-2020-21674 Anchore CVE Medium libarchive-3.3.3-4.el8
CVE-2020-19190 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2018-20839 Anchore CVE Medium systemd-libs-239-68.el8_7.4
CVE-2023-50495 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2023-27534 Anchore CVE Low libcurl-7.61.1-25.el8_7.3
CVE-2018-1000654 Anchore CVE Low libtasn1-4.13-4.el8_7
CVE-2018-19217 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2018-19211 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2019-17543 Anchore CVE Medium lz4-libs-1.8.3-3.el8_4
CVE-2020-19189 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2023-36191 Anchore CVE Low sqlite-libs-3.26.0-17.el8_7
CVE-2023-45322 Anchore CVE Low libxml2-2.9.7-15.el8_7.1
CVE-2020-35512 Anchore CVE Low dbus-common-1:1.12.8-23.el8_7.1
CVE-2024-25260 Anchore CVE Low elfutils-default-yama-scope-0.187-4.el8
CVE-2020-19188 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2022-0235 Anchore CVE Medium python3-subscription-manager-rhsm-1.28.32-1.el8
CVE-2024-25260 Anchore CVE Low elfutils-libelf-0.187-4.el8
CVE-2023-4156 Anchore CVE Low gawk-4.2.1-4.el8
CVE-2021-33294 Anchore CVE Low elfutils-default-yama-scope-0.187-4.el8
CVE-2019-19244 Anchore CVE Low sqlite-libs-3.26.0-17.el8_7
CVE-2021-3997 Anchore CVE Medium systemd-libs-239-68.el8_7.4
CVE-2022-0235 Anchore CVE Medium subscription-manager-rhsm-certificates-1.28.32-1.el8
CVE-2020-12413 Anchore CVE Low nss-3.79.0-11.el8_7
CVE-2020-19187 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2020-19185 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2021-42694 Anchore CVE Medium libstdc++-8.5.0-16.el8_7
CVE-2018-20657 Anchore CVE Low libgcc-8.5.0-16.el8_7
CVE-2018-1000879 Anchore CVE Low libarchive-3.3.3-4.el8
CVE-2023-50495 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2023-32636 Anchore CVE Low glib2-2.56.4-159.el8
CVE-2021-39537 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2021-42694 Anchore CVE Medium libgcc-8.5.0-16.el8_7
CVE-2022-0235 Anchore CVE Medium python3-syspurpose-1.28.32-1.el8
CVE-2021-4209 Anchore CVE Low gnutls-3.6.16-6.el8_7
CVE-2023-39804 Anchore CVE Low tar-2:1.30-6.el8_7.1
CVE-2024-0232 Anchore CVE Low sqlite-libs-3.26.0-17.el8_7
CVE-2019-12904 Anchore CVE Medium libgcrypt-1.8.5-7.el8_6
CVE-2018-19217 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2021-39537 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2020-19190 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2005-2541 Anchore CVE Medium tar-2:1.30-6.el8_7.1
CVE-2022-0235 Anchore CVE Medium subscription-manager-1.28.32-1.el8
CVE-2018-1000880 Anchore CVE Low libarchive-3.3.3-4.el8
CVE-2022-23990 Anchore CVE Medium expat-2.2.5-10.el8_7.1
CVE-2019-9674 Anchore CVE Low python3-libs-3.6.8-48.el8_7.1
CVE-2020-19186 Anchore CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2018-20225 Anchore CVE Low python3-pip-wheel-9.0.3-22.el8
CVE-2019-1010022 Anchore CVE Critical glibc-common-2.28-211.el8
CVE-2020-12413 Anchore CVE Low nss-softokn-freebl-3.79.0-11.el8_7
CVE-2020-19186 Anchore CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2022-27943 Anchore CVE Low libstdc++-8.5.0-16.el8_7
CVE-2019-8905 Anchore CVE Low file-libs-5.33-21.el8
CVE-2023-43804 Anchore CVE Medium python3-pip-wheel-9.0.3-22.el8
GHSA-g7vv-2v7x-gj9p Anchore CVE Low tqdm-4.64.1
GHSA-h75v-3vvj-5mfj Anchore CVE Medium Jinja2-3.1.2
CVE-2023-52425 OSCAP Compliance Medium
CVE-2023-28322 OSCAP Compliance Medium
CVE-2023-38546 OSCAP Compliance Medium
CVE-2023-46218 OSCAP Compliance Medium
CVE-2024-28834 OSCAP Compliance Medium
CVE-2024-2961 OSCAP Compliance Medium
CVE-2023-6597 OSCAP Compliance Medium
CVE-2024-0450 OSCAP Compliance Medium
CVE-2024-33599 OSCAP Compliance Medium
CVE-2024-33600 OSCAP Compliance Medium
CVE-2024-33601 OSCAP Compliance Medium
CVE-2024-33602 OSCAP Compliance Medium
CVE-2024-26458 OSCAP Compliance Medium
CVE-2024-26461 OSCAP Compliance Medium
CVE-2023-6004 OSCAP Compliance Medium
CVE-2023-6918 OSCAP Compliance Medium
CVE-2021-43618 OSCAP Compliance Medium
CVE-2023-7008 OSCAP Compliance Medium
CVE-2024-22365 OSCAP Compliance Medium
CVE-2023-27043 Twistlock CVE Medium python3-libs-3.6.8-48.el8_7.1
CVE-2023-27043 Twistlock CVE Medium platform-python-3.6.8-48.el8_7.1
CVE-2023-2283 Twistlock CVE Medium libssh-config-0.9.6-3.el8
CVE-2023-2283 Twistlock CVE Medium libssh-0.9.6-3.el8
CVE-2023-2800 Twistlock CVE Medium transformers-4.24.0
CVE-2023-6135 Twistlock CVE Medium nss-sysinit-3.79.0-11.el8_7
CVE-2023-6135 Twistlock CVE Medium nss-util-3.79.0-11.el8_7
CVE-2023-6135 Twistlock CVE Medium nss-softokn-freebl-3.79.0-11.el8_7
CVE-2023-6135 Twistlock CVE Medium nss-3.79.0-11.el8_7
CVE-2023-6135 Twistlock CVE Medium nss-softokn-3.79.0-11.el8_7
CVE-2023-1667 Twistlock CVE Medium libssh-0.9.6-3.el8
CVE-2023-1667 Twistlock CVE Medium libssh-config-0.9.6-3.el8
CVE-2023-45803 Twistlock CVE Medium python3-urllib3-1.24.2-5.el8
GHSA-74m5-2c7w-9w3x Twistlock CVE Medium starlette-0.20.4
CVE-2023-37920 Twistlock CVE Low ca-certificates-2022.2.54-80.2.el8_6
CVE-2024-26461 Twistlock CVE Low krb5-libs-1.18.2-22.el8_7
CVE-2024-26458 Twistlock CVE Low krb5-libs-1.18.2-22.el8_7
CVE-2023-2953 Twistlock CVE Low openldap-2.4.46-18.el8
CVE-2023-50495 Twistlock CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2023-50495 Twistlock CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2023-32665 Twistlock CVE Low glib2-2.56.4-159.el8
CVE-2023-32611 Twistlock CVE Low glib2-2.56.4-159.el8
CVE-2023-2650 Twistlock CVE Low openssl-libs-1.1.1k-9.el8_7
CVE-2020-19190 Twistlock CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2020-19190 Twistlock CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2020-19189 Twistlock CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2020-19189 Twistlock CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2020-19188 Twistlock CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2020-19188 Twistlock CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2020-19187 Twistlock CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2020-19187 Twistlock CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2020-19186 Twistlock CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2020-19186 Twistlock CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2020-19185 Twistlock CVE Low ncurses-libs-6.1-9.20180224.el8
CVE-2020-19185 Twistlock CVE Low ncurses-base-6.1-9.20180224.el8
CVE-2023-32636 Twistlock CVE Low glib2-2.56.4-159.el8
CVE-2023-29499 Twistlock CVE Low glib2-2.56.4-159.el8
CVE-2023-6004 Twistlock CVE Low libssh-config-0.9.6-3.el8
CVE-2023-6004 Twistlock CVE Low libssh-0.9.6-3.el8
CVE-2023-4156 Twistlock CVE Low gawk-4.2.1-4.el8
CVE-2024-0727 Twistlock CVE Low openssl-libs-1.1.1k-9.el8_7
CVE-2022-47011 Twistlock CVE Low gdb-gdbserver-8.2-19.el8
CVE-2022-47010 Twistlock CVE Low gdb-gdbserver-8.2-19.el8
CVE-2022-47007 Twistlock CVE Low gdb-gdbserver-8.2-19.el8
CVE-2023-5678 Twistlock CVE Low openssl-libs-1.1.1k-9.el8_7
CVE-2023-3817 Twistlock CVE Low openssl-libs-1.1.1k-9.el8_7
CVE-2023-3446 Twistlock CVE Low openssl-libs-1.1.1k-9.el8_7
CVE-2022-41409 Twistlock CVE Low pcre2-10.32-3.el8_6
CVE-2024-0232 Twistlock CVE Low sqlite-libs-3.26.0-17.el8_7
CVE-2023-4641 Twistlock CVE Low shadow-utils-4.6-17.el8
CVE-2024-25260 Twistlock CVE Low elfutils-libs-0.187-4.el8
CVE-2024-25260 Twistlock CVE Low elfutils-libelf-0.187-4.el8
CVE-2024-25260 Twistlock CVE Low elfutils-default-yama-scope-0.187-4.el8
CVE-2021-33294 Twistlock CVE Low elfutils-libs-0.187-4.el8
CVE-2021-33294 Twistlock CVE Low elfutils-default-yama-scope-0.187-4.el8
CVE-2021-33294 Twistlock CVE Low elfutils-libelf-0.187-4.el8
CVE-2023-6918 Twistlock CVE Low libssh-config-0.9.6-3.el8
CVE-2023-6918 Twistlock CVE Low libssh-0.9.6-3.el8
CVE-2023-38546 Twistlock CVE Low libcurl-7.61.1-25.el8_7.3
CVE-2023-38546 Twistlock CVE Low curl-7.61.1-25.el8_7.3
CVE-2023-28322 Twistlock CVE Low libcurl-7.61.1-25.el8_7.3
CVE-2023-28322 Twistlock CVE Low curl-7.61.1-25.el8_7.3
CVE-2023-39804 Twistlock CVE Low tar-1.30-6.el8_7.1
CVE-2023-2602 Twistlock CVE Low libcap-2.48-4.el8
CVE-2024-2236 Twistlock CVE Medium libgcrypt-1.8.5-7.el8_6
CVE-2024-28834 Twistlock CVE Medium gnutls-3.6.16-6.el8_7
CVE-2024-2398 Twistlock CVE Medium libcurl-7.61.1-25.el8_7.3
CVE-2024-2398 Twistlock CVE Medium curl-7.61.1-25.el8_7.3
CVE-2024-28182 Twistlock CVE Medium libnghttp2-1.33.0-3.el8_2.1
CVE-2024-3205 Twistlock CVE Medium libyaml-0.1.7-5.el8
CVE-2024-28219 Twistlock CVE Medium pillow-9.2.0
CVE-2024-2511 Twistlock CVE Low openssl-libs-1.1.1k-9.el8_7
CVE-2024-3651 Twistlock CVE Medium idna-3.4
CVE-2024-3568 Twistlock CVE Low transformers-4.24.0
CVE-2024-1135 Twistlock CVE High gunicorn-20.1.0
CVE-2024-2961 Twistlock CVE Critical glibc-common-2.28-211.el8
CVE-2024-2961 Twistlock CVE Critical glibc-minimal-langpack-2.28-211.el8
CVE-2024-2961 Twistlock CVE Critical glibc-2.28-211.el8
CVE-2023-6597 Twistlock CVE Critical platform-python-3.6.8-48.el8_7.1
CVE-2023-6597 Twistlock CVE Critical python3-libs-3.6.8-48.el8_7.1
CVE-2024-0450 Twistlock CVE Medium platform-python-3.6.8-48.el8_7.1
CVE-2024-0450 Twistlock CVE Medium python3-libs-3.6.8-48.el8_7.1
CVE-2024-3772 Twistlock CVE Medium pydantic-1.10.2
CVE-2023-43804 Twistlock CVE Medium python3-pip-wheel-9.0.3-22.el8
CVE-2024-29040 Twistlock CVE Medium tpm2-tss-2.3.2-4.el8
CVE-2024-34062 Twistlock CVE Low tqdm-4.64.1
CVE-2024-34064 Twistlock CVE Medium jinja2-3.1.2
CVE-2023-37920 Twistlock CVE Critical certifi-2022.9.24
CVE-2023-50447 Twistlock CVE High pillow-9.2.0
CVE-2023-43804 Twistlock CVE High urllib3-1.26.12
CVE-2023-44271 Twistlock CVE High pillow-9.2.0
CVE-2023-30798 Twistlock CVE High starlette-0.20.4
CVE-2023-29159 Twistlock CVE High starlette-0.20.4
CVE-2024-22195 Twistlock CVE Medium jinja2-3.1.2
CVE-2023-32681 Twistlock CVE Medium requests-2.28.1
CVE-2023-45803 Twistlock CVE Medium urllib3-1.26.12
CVE-2024-34397 Twistlock CVE Medium glib2-2.56.4-159.el8
CVE-2024-34459 Twistlock CVE Medium python3-libxml2-2.9.7-15.el8_7.1
CVE-2024-34459 Twistlock CVE Low libxml2-2.9.7-15.el8_7.1
CVE-2024-35195 Twistlock CVE Medium requests-2.28.1

VAT: https://vat.dso.mil/vat/image?imageName=aperio-global/russel/unstructured-data-processing&tag=1.0&branch=master
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=aperio-global/russel/unstructured-data-processing&tag=1.0&branch=master

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the ~"Hardening::Verification" label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Verification label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by Damian Watkins
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information