UNCLASSIFIED - NO CUI

Skip to content

chore(findings): big-bang/edge-controller

Summary

big-bang/edge-controller has 29 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=big-bang/edge-controller&tag=0.2.0&branch=master

EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.

id source severity package impact workaround epss_score kev
CVE-2025-32728 Twistlock CVE Medium openssh-8.7p1-45.el9 0.00033 false
CVE-2025-32728 Anchore CVE Medium openssh-clients-8.7p1-45.el9 0.00033 false
CVE-2025-32728 Anchore CVE Medium openssh-8.7p1-45.el9 0.00033 false
CVE-2025-50181 Anchore CVE Medium python3-pip-21.3.1-1.el9 0.00015 false
CVE-2025-50182 Anchore CVE Medium python3-pip-21.3.1-1.el9 0.00013 false
fc295fb1750b6433ac0c42d305b67ca4 Anchore Compliance Critical N/A N/A
f98378afc5ad97d2e20ca90d32d5dbb9 Anchore Compliance Critical N/A N/A
f920e4f79a062d08b823020ef0934d03 Anchore Compliance Critical N/A N/A
f67f05db309f75c904137830d0dc55ac Anchore Compliance Critical N/A N/A
e84c089c086f97b6a2a2e8273230bae3 Anchore Compliance Critical N/A N/A
de85f9d5fcfd24e15dd643bffe7b2c58 Anchore Compliance Critical N/A N/A
c2b65250c4081e745b2b6bd78c06d145 Anchore Compliance Critical N/A N/A
bcf544fd6786d31713281e6301a72c26 Anchore Compliance Critical N/A N/A
b94229e1ad276fe5b9611d0925152aaf Anchore Compliance Critical N/A N/A
aab3782110ffe014f3e2fa7bad8e2d0a Anchore Compliance Critical N/A N/A
PRISMA-2022-0168 Twistlock CVE High pip-21.3.1 N/A N/A
9ef6ce16825018fd56c57fe22a538dad Anchore Compliance Critical N/A N/A
953dfbea1b1e9d5829fbed2e390bd3af Anchore Compliance Critical N/A N/A
8e9e321f6c7e3f73cecbb3df2d68906b Anchore Compliance Critical N/A N/A
8cba43b94cf18cd7f0b61522835c316d Anchore Compliance Critical N/A N/A
7ca1d2981cd2ca7c4c9acebbcd6bef33 Anchore Compliance Critical N/A N/A
7c8d61664b54d2beaaf3b1217caac250 Anchore Compliance Critical N/A N/A
5ab6bf90e2244496bf8df3220e3d3b90 Anchore Compliance Critical N/A N/A
57c1a113257f69389ac08c0f75f728b5 Anchore Compliance Critical N/A N/A
5034ba70930bc60e0bb319ce4c2b718c Anchore Compliance Critical N/A N/A
1e0ac973c918de283b7d2eed1d3efd04 Anchore Compliance Critical N/A N/A
173f0a139b87b9647319f8e4afa6e023 Anchore Compliance Critical N/A N/A
041dcd8ce728279138aa302ab6a4d0cb Anchore Compliance Critical N/A N/A
0335d4fd8f3b76e1dde13c5ac7296387 Anchore Compliance Critical N/A N/A

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=big-bang/edge-controller&tag=0.2.0&branch=master

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Verification label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by CHORE_TOKEN
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information