chore(findings): big-bang/babu
Summary
big-bang/babu has 304 new findings discovered during continuous monitoring.
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=big-bang/babu&tag=0.3.4&branch=master
id | source | severity | package | impact | workaround |
---|---|---|---|---|---|
CVE-2022-47007 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2021-3826 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2022-0529 | Anchore CVE | Low | unzip-6.0-56.el9 | ||
CVE-2024-4032 | Anchore CVE | High | python-3.11.9 | ||
CVE-2024-24789 | Anchore CVE | Medium | stdlib-go1.22.3 | ||
CVE-2024-26461 | Anchore CVE | Low | krb5-devel-1.21.1-2.el9_4 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.22.5 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.22.5 | ||
CVE-2022-41409 | Anchore CVE | Low | pcre2-utf32-10.40-5.el9 | ||
CVE-2023-38898 | Anchore CVE | Medium | python-3.11.9 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.13 | ||
CVE-2024-26458 | Anchore CVE | Low | krb5-devel-1.21.1-2.el9_4 | ||
CVE-2024-7592 | Anchore CVE | High | python-3.11.9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.22.6 | ||
CVE-2021-4217 | Anchore CVE | Low | unzip-6.0-56.el9 | ||
CVE-2023-2222 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2023-1579 | Anchore CVE | Medium | binutils-2.35.2-43.el9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.22.6 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.13 | ||
CVE-2023-38898 | Anchore CVE | Medium | python-3.11.9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2022-47011 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2023-1972 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.13 | ||
CVE-2024-6232 | Anchore CVE | Medium | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2021-3997 | Anchore CVE | Medium | systemd-udev-252-32.el9_4.7 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.22.5 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.22.5 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.12 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2023-7207 | Anchore CVE | Medium | cpio-2.13-16.el9 | ||
CVE-2022-38533 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2024-4032 | Anchore CVE | High | python-3.11.9 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.22.3 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.22.3 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.22.5 | ||
CVE-2024-7592 | Anchore CVE | High | python-3.11.9 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2022-38533 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-24791 | Anchore CVE | High | stdlib-go1.22.3 | ||
CVE-2022-47010 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.12 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.13 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2024-26462 | Anchore CVE | Medium | libkadm5-1.21.1-2.el9_4 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.22.5 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2023-51767 | Anchore CVE | Medium | openssh-8.7p1-38.el9_4.4 | ||
GHSA-v23v-6jw2-98fq | Anchore CVE | Critical | github.com/docker/docker-v25.0.5+incompatible | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2022-27943 | Anchore CVE | Low | gcc-11.4.1-3.el9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.22.5 | ||
CVE-2023-1972 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2023-7216 | Anchore CVE | Low | cpio-2.13-16.el9 | ||
CVE-2024-6232 | Anchore CVE | High | python-3.11.9 | ||
CVE-2023-24056 | Anchore CVE | Low | pkgconf-pkg-config-1.7.3-10.el9 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.13 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2023-24056 | Anchore CVE | Low | pkgconf-1.7.3-10.el9 | ||
CVE-2021-23336 | Anchore CVE | Medium | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2021-45078 | Anchore CVE | Medium | binutils-2.35.2-43.el9 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.22.6 | ||
CVE-2022-47010 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
GHSA-jpxc-vmjf-9fcj | Anchore CVE | Medium | ansible-core-2.15.12 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-8088 | Anchore CVE | Low | python-3.11.9 | ||
CVE-2021-32256 | Anchore CVE | Medium | binutils-2.35.2-43.el9 | ||
GHSA-jfvp-7x6p-h2pv | Anchore CVE | Low | github.com/opencontainers/runc-v1.1.13 | ||
CVE-2024-24790 | Anchore CVE | Critical | stdlib-go1.22.3 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2021-45078 | Anchore CVE | Medium | binutils-gold-2.35.2-43.el9 | ||
CVE-2024-25260 | Anchore CVE | Low | elfutils-debuginfod-client-0.190-2.el9 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.22.5 | ||
CVE-2024-24790 | Twistlock CVE | Critical | net/netip-1.22.3 | ||
CVE-2019-14271 | Twistlock CVE | Critical | github.com/docker/docker/pkg/chrootarchive-1.21.13 | ||
PRISMA-2022-0168 | Twistlock CVE | High | pip-21.2.3 | ||
PRISMA-2022-0227 | Twistlock CVE | High | github.com/emicklei/go-restful/v3-v3.8.0 | ||
CVE-2022-36049 | Twistlock CVE | High | helm.sh/helm/v3/pkg/strvals-1.22.6 | ||
CVE-2024-33663 | Twistlock CVE | High | python-jose-3.3.0 | ||
CVE-2024-23342 | Twistlock CVE | High | ecdsa-0.19.0 | ||
CVE-2024-26147 | Twistlock CVE | High | helm.sh/helm/v3/pkg/repo-1.22.6 | ||
CVE-2024-26147 | Twistlock CVE | High | helm.sh/helm/v3/pkg/plugin-1.22.6 | ||
CVE-2021-32690 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/downloader-1.22.6 | ||
CVE-2024-24557 | Twistlock CVE | Medium | github.com/docker/docker/builder/dockerfile-1.21.13 | ||
CVE-2024-24557 | Twistlock CVE | Medium | github.com/docker/docker/daemon/containerd-1.21.13 | ||
CVE-2024-24557 | Twistlock CVE | Medium | github.com/docker/docker/image-1.21.13 | ||
CVE-2024-24557 | Twistlock CVE | Medium | github.com/docker/docker/daemon/images-1.21.13 | ||
CVE-2024-24557 | Twistlock CVE | Medium | github.com/docker/docker/image/cache-1.21.13 | ||
CVE-2021-45078 | Twistlock CVE | Medium | binutils-gold-2.35.2-43.el9 | ||
CVE-2021-45078 | Twistlock CVE | Medium | binutils-2.35.2-43.el9 | ||
CVE-2024-6232 | Twistlock CVE | Medium | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2024-26462 | Twistlock CVE | Medium | krb5-devel-1.21.1-2.el9_4 | ||
CVE-2024-26462 | Twistlock CVE | Medium | libkadm5-1.21.1-2.el9_4 | ||
CVE-2022-23526 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/chartutil-1.22.6 | ||
CVE-2022-23525 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/repo-1.22.6 | ||
CVE-2022-23524 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/strvals-1.22.6 | ||
CVE-2019-19204 | Twistlock CVE | Medium | oniguruma-6.9.6-1.el9.5 | ||
CVE-2019-19203 | Twistlock CVE | Medium | oniguruma-6.9.6-1.el9.5 | ||
CVE-2023-51767 | Twistlock CVE | Medium | openssh-8.7p1-38.el9_4.4 | ||
CVE-2023-51767 | Twistlock CVE | Medium | openssh-server-8.7p1-38.el9_4.4 | ||
CVE-2023-1579 | Twistlock CVE | Medium | binutils-2.35.2-43.el9 | ||
CVE-2023-1579 | Twistlock CVE | Medium | binutils-gold-2.35.2-43.el9 | ||
CVE-2019-13224 | Twistlock CVE | Medium | oniguruma-6.9.6-1.el9.5 | ||
CVE-2019-16163 | Twistlock CVE | Medium | oniguruma-6.9.6-1.el9.5 | ||
CVE-2021-41091 | Twistlock CVE | Medium | github.com/docker/docker/daemon/graphdriver/btrfs-1.21.13 | ||
CVE-2021-41091 | Twistlock CVE | Medium | github.com/docker/docker/daemon/graphdriver/fuse-overlayfs-1.21.13 | ||
CVE-2021-41091 | Twistlock CVE | Medium | github.com/docker/docker/daemon-1.21.13 | ||
CVE-2021-41091 | Twistlock CVE | Medium | github.com/docker/docker/daemon/graphdriver/vfs-1.21.13 | ||
CVE-2021-41091 | Twistlock CVE | Medium | github.com/docker/docker/daemon/graphdriver/zfs-1.21.13 | ||
CVE-2021-41091 | Twistlock CVE | Medium | github.com/docker/docker/daemon/graphdriver/overlay2-1.21.13 | ||
PRISMA-2023-0056 | Twistlock CVE | Medium | github.com/sirupsen/logrus-v1.9.1 | ||
CVE-2021-23336 | Twistlock CVE | Medium | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2024-8775 | Twistlock CVE | Medium | ansible-core-2.15.12 | ||
CVE-2023-7207 | Twistlock CVE | Medium | cpio-2.13-16.el9 | ||
CVE-2021-3997 | Twistlock CVE | Medium | systemd-udev-252-32.el9_4.7 | ||
PRISMA-2022-0404 | Twistlock CVE | Medium | wheel-0.36.2 | ||
CVE-2024-8088 | Twistlock CVE | Medium | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2024-33664 | Twistlock CVE | Medium | python-jose-3.3.0 | ||
CVE-2017-9226 | Twistlock CVE | Medium | oniguruma-6.9.6-1.el9.5 | ||
CVE-2023-25165 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/engine-1.22.6 | ||
CVE-2023-25165 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/action-1.22.6 | ||
CVE-2021-20197 | Twistlock CVE | Medium | binutils-gold-2.35.2-43.el9 | ||
CVE-2021-20197 | Twistlock CVE | Medium | binutils-2.35.2-43.el9 | ||
CVE-2024-25620 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/lint/rules-1.22.6 | ||
CVE-2024-25620 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/chart-1.22.6 | ||
CVE-2024-25620 | Twistlock CVE | Medium | helm.sh/helm/v3/pkg/chartutil-1.22.6 | ||
CVE-2022-44840 | Twistlock CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2022-44840 | Twistlock CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2021-3826 | Twistlock CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2021-3826 | Twistlock CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2021-41089 | Twistlock CVE | Low | github.com/docker/docker/pkg/chrootarchive-1.21.13 | ||
CVE-2024-26461 | Twistlock CVE | Low | krb5-devel-1.21.1-2.el9_4 | ||
CVE-2024-26461 | Twistlock CVE | Low | libkadm5-1.21.1-2.el9_4 | ||
CVE-2024-26458 | Twistlock CVE | Low | krb5-devel-1.21.1-2.el9_4 | ||
CVE-2024-26458 | Twistlock CVE | Low | libkadm5-1.21.1-2.el9_4 | ||
CVE-2023-24056 | Twistlock CVE | Low | libpkgconf-1.7.3-10.el9 | ||
CVE-2023-24056 | Twistlock CVE | Low | pkgconf-pkg-config-1.7.3-10.el9 | ||
CVE-2023-24056 | Twistlock CVE | Low | pkgconf-1.7.3-10.el9 | ||
CVE-2023-24056 | Twistlock CVE | Low | pkgconf-m4-1.7.3-10.el9 | ||
CVE-2022-47011 | Twistlock CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2022-47011 | Twistlock CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2022-47010 | Twistlock CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2022-47010 | Twistlock CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2022-47008 | Twistlock CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2022-47008 | Twistlock CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2022-47007 | Twistlock CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2022-47007 | Twistlock CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2022-38533 | Twistlock CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2022-38533 | Twistlock CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2022-27943 | Twistlock CVE | Low | cpp-11.4.1-3.el9 | ||
CVE-2022-27943 | Twistlock CVE | Low | gcc-11.4.1-3.el9 | ||
CVE-2022-0530 | Twistlock CVE | Low | unzip-6.0-56.el9 | ||
CVE-2022-0529 | Twistlock CVE | Low | unzip-6.0-56.el9 | ||
CVE-2023-7216 | Twistlock CVE | Low | cpio-2.13-16.el9 | ||
CVE-2022-41409 | Twistlock CVE | Low | pcre2-devel-10.40-5.el9 | ||
CVE-2022-41409 | Twistlock CVE | Low | pcre2-utf32-10.40-5.el9 | ||
CVE-2022-41409 | Twistlock CVE | Low | pcre2-utf16-10.40-5.el9 | ||
CVE-2024-0397 | Twistlock CVE | Low | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2024-7592 | Twistlock CVE | Low | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2019-19246 | Twistlock CVE | Low | oniguruma-6.9.6-1.el9.5 | ||
CVE-2021-3572 | Twistlock CVE | Low | python3-pip-21.2.3-8.el9 | ||
CVE-2024-25260 | Twistlock CVE | Low | elfutils-debuginfod-client-0.190-2.el9 | ||
CVE-2021-4217 | Twistlock CVE | Low | unzip-6.0-56.el9 | ||
CVE-2023-1972 | Twistlock CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2023-1972 | Twistlock CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2015-1197 | Twistlock CVE | Low | cpio-2.13-16.el9 | ||
CVE-2024-45310 | Twistlock CVE | Low | github.com/opencontainers/runc-v1.1.13 | ||
CVE-2024-34156 | Twistlock CVE | Low | encoding/gob-1.21.12 | ||
CVE-2024-34156 | Twistlock CVE | Low | encoding/gob-1.22.5 | ||
CVE-2024-34156 | Twistlock CVE | Low | encoding/gob-1.22.3 | ||
CVE-2024-34156 | Twistlock CVE | Low | encoding/gob-1.21.13 | ||
CVE-2024-34155 | Twistlock CVE | Low | go/parser-1.22.5 | ||
CVE-2024-34155 | Twistlock CVE | Low | go/parser-1.22.3 | ||
CVE-2024-34155 | Twistlock CVE | Low | go/parser-1.22.6 | ||
CVE-2024-34155 | Twistlock CVE | Low | go/parser-1.21.13 | ||
CVE-2024-24791 | Twistlock CVE | Low | net/http-1.22.3 | ||
cbff271f45d32e78dcc1979dbca9c14d | Anchore Compliance | Critical | |||
953dfbea1b1e9d5829fbed2e390bd3af | Anchore Compliance | Critical | |||
dd33f9ae335b0724372e0508851608ba | Anchore Compliance | Critical | |||
cad4b9e1d8bc37e8f61b8c80273e1504 | Anchore Compliance | Critical | |||
5f85284d8feacd52f4064c60fcd65a05 | Anchore Compliance | Critical | |||
5444e41a650558f12b46d6f90aeeebd4 | Anchore Compliance | Critical | |||
65ed7d01a4c991f2a0dca773fbc5b38c | Anchore Compliance | Critical | |||
39649726760cba7c25d069c27b7e2cd4 | Anchore Compliance | Critical | |||
bcd88662e56d377e43741f705a8b9120 | Anchore Compliance | Critical | |||
e6392bd72780279e200a6f3a2eef10d5 | Anchore Compliance | Critical | |||
667e92e4efc9af22a4d35562e5cf2329 | Anchore Compliance | Critical | |||
4a931bd64649cda9a22eb8f4b15fadd5 | Anchore Compliance | Critical | |||
1214122853aa990743d3ea8f1b5c2e5d | Anchore Compliance | Critical | |||
102a2875068455326ed86368b290042a | Anchore Compliance | Critical | |||
07c41810f980929fb0eec739d35067fb | Anchore Compliance | Critical | |||
42fe400a7eea10116f8d2bede3d3bfeb | Anchore Compliance | Critical | |||
6c1411888e78c5063bc04d8680caa7d0 | Anchore Compliance | Critical | |||
be5f7fe9aa8f792ad96017c83da0a841 | Anchore Compliance | Critical | |||
546cbf728937f68d4c9fda90b87cd083 | Anchore Compliance | Critical | |||
2b8c2ba1cb07dfd88c8eb7cbaeed8aaf | Anchore Compliance | Critical | |||
652d6848d0e9f2fb1f648439b5aaec20 | Anchore Compliance | Critical | |||
9dd2ceccecac9795334b69633cd694f1 | Anchore Compliance | Critical | |||
8450b6033f514eac0e0227e1d610e138 | Anchore Compliance | Critical | |||
44ad73eb468c7b410f603a9ca91822c9 | Anchore Compliance | Critical | |||
21895dc508518831dbf4cd8c24817a3a | Anchore Compliance | Critical | |||
e7e64925c8420f9f28bc0653931b47d0 | Anchore Compliance | Critical | |||
dce4988c6729e5c947f16c73de8908d0 | Anchore Compliance | Critical | |||
594c0473daee33007e75f1c2cccab922 | Anchore Compliance | Critical | |||
ec5f98436d017703738ecbb742baf57e | Anchore Compliance | Critical | |||
fce0fb30161625c269f6dab20d5c5a91 | Anchore Compliance | Critical | |||
a6762d8b822bf8141df10117afeabae8 | Anchore Compliance | Critical | |||
c89a2e599e0d4226cf978acbbe1cef9f | Anchore Compliance | Critical | |||
dbc3e6681a5a3dd6b58c9fe052787cfd | Anchore Compliance | Critical | |||
d37063184465d055429f44c24c5af7ff | Anchore Compliance | Critical | |||
aab3782110ffe014f3e2fa7bad8e2d0a | Anchore Compliance | Critical | |||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.12 | ||
CVE-2024-6923 | Anchore CVE | Medium | python-3.11.9 | ||
CVE-2024-8088 | Anchore CVE | Low | python-3.11.9 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.22.6 | ||
CVE-2023-1579 | Anchore CVE | Medium | binutils-gold-2.35.2-43.el9 | ||
CVE-2024-6923 | Anchore CVE | Medium | python-3.11.9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.22.5 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2021-3572 | Anchore CVE | Low | python3-pip-21.2.3-8.el9 | ||
GHSA-cjwg-qfpm-7377 | Anchore CVE | Medium | python-jose-3.3.0 | ||
CVE-2023-24056 | Anchore CVE | Low | libpkgconf-1.7.3-10.el9 | ||
CVE-2024-23342 | Anchore CVE | High | ecdsa-0.19.0 | ||
CVE-2024-26462 | Anchore CVE | Medium | krb5-devel-1.21.1-2.el9_4 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.12 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.13 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.22.5 | ||
CVE-2021-32256 | Anchore CVE | Medium | binutils-gold-2.35.2-43.el9 | ||
CVE-2024-26461 | Anchore CVE | Low | libkadm5-1.21.1-2.el9_4 | ||
CVE-2022-44840 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2021-20197 | Anchore CVE | Medium | binutils-gold-2.35.2-43.el9 | ||
CVE-2024-26458 | Anchore CVE | Low | libkadm5-1.21.1-2.el9_4 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.22.6 | ||
CVE-2021-3826 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2021-20197 | Anchore CVE | Medium | binutils-2.35.2-43.el9 | ||
CVE-2022-47007 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2023-24056 | Anchore CVE | Low | pkgconf-m4-1.7.3-10.el9 | ||
CVE-2022-27943 | Anchore CVE | Low | cpp-11.4.1-3.el9 | ||
CVE-2015-1197 | Anchore CVE | Low | cpio-2.13-16.el9 | ||
GHSA-6c5p-j8vq-pqhj | Anchore CVE | High | python-jose-3.3.0 | ||
CVE-2024-23332 | Anchore CVE | Medium | github.com/notaryproject/notation-go-v1.2.1 | ||
CVE-2024-7592 | Anchore CVE | Low | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2022-47008 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2016-20012 | Anchore CVE | Low | openssh-8.7p1-38.el9_4.4 | ||
GHSA-jfvp-7x6p-h2pv | Anchore CVE | Low | github.com/opencontainers/runc-v1.1.13-0-g58aa920 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.12 | ||
CVE-2022-41409 | Anchore CVE | Low | pcre2-devel-10.40-5.el9 | ||
CVE-2023-36632 | Anchore CVE | Medium | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2022-41409 | Anchore CVE | Low | pcre2-utf16-10.40-5.el9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2016-20012 | Anchore CVE | Low | openssh-server-8.7p1-38.el9_4.4 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.13 | ||
CVE-2023-2222 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.22.3 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.22.5 | ||
CVE-2022-44840 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.22.6 | ||
CVE-2024-6232 | Anchore CVE | High | python-3.11.9 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2022-0530 | Anchore CVE | Low | unzip-6.0-56.el9 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.13 | ||
CVE-2024-34155 | Anchore CVE | Low | stdlib-go1.21.13 | ||
CVE-2024-34158 | Anchore CVE | High | stdlib-go1.21.12 | ||
CVE-2022-47011 | Anchore CVE | Low | binutils-2.35.2-43.el9 | ||
CVE-2022-47008 | Anchore CVE | Low | binutils-gold-2.35.2-43.el9 | ||
CVE-2024-8088 | Anchore CVE | Medium | python3-devel-3.9.18-3.el9_4.5 | ||
CVE-2024-34156 | Anchore CVE | High | stdlib-go1.22.5 | ||
CVE-2023-51767 | Anchore CVE | Medium | openssh-server-8.7p1-38.el9_4.4 | ||
CCE-90029-0 | OSCAP Compliance | Medium | |||
CCE-83529-8 | OSCAP Compliance | Medium | |||
CCE-83908-4 | OSCAP Compliance | Medium | |||
CCE-83911-8 | OSCAP Compliance | Medium | |||
CCE-90805-3 | OSCAP Compliance | Medium | |||
CCE-90811-1 | OSCAP Compliance | Medium | |||
CCE-90816-0 | OSCAP Compliance | Medium | |||
CCE-90801-2 | OSCAP Compliance | Medium | |||
CCE-90799-8 | OSCAP Compliance | High | |||
CCE-90808-7 | OSCAP Compliance | Medium | |||
CCE-90802-0 | OSCAP Compliance | Medium | |||
CCE-90797-2 | OSCAP Compliance | Medium | |||
CCE-90800-4 | OSCAP Compliance | Medium | |||
CCE-90796-4 | OSCAP Compliance | Medium | |||
CCE-90798-0 | OSCAP Compliance | Medium | |||
CCE-90803-8 | OSCAP Compliance | Medium | |||
CCE-86138-5 | OSCAP Compliance | Medium | |||
CCE-90809-5 | OSCAP Compliance | Medium | |||
CCE-90807-9 | OSCAP Compliance | Medium | |||
CCE-90804-6 | OSCAP Compliance | Medium | |||
CCE-90815-2 | OSCAP Compliance | Medium | |||
CCE-86923-0 | OSCAP Compliance | Medium | |||
CCE-88822-2 | OSCAP Compliance | Medium | |||
CCE-89105-1 | OSCAP Compliance | Medium |
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=big-bang/babu&tag=0.3.4&branch=master
Tasks
Contributor:
-
Provide justifications for findings in the VAT (docs) -
Apply the StatusVerification label to this issue and wait for feedback
Iron Bank:
-
Review findings and justifications
Note: If the above process is rejected for any reason, the
Verification
label will be removed and the issue will be sent back toOpen
. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add theVerification
label.
Questions?
Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding
.
Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.