UNCLASSIFIED - NO CUI

Skip to content

chore(findings): ccj2-a3im/datahub/datahub-actions

Summary

ccj2-a3im/datahub/datahub-actions has 501 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=ccj2-a3im/datahub/datahub-actions&tag=v0.2.1&branch=master

EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.

id source severity package impact workaround epss_score kev
CVE-2023-44487 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.94437 true
CVE-2023-44487 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.94437 true
CVE-2022-1471 Twistlock CVE Critical org.yaml_snakeyaml-1.31 0.93796 N/A
CVE-2023-2650 Anchore CVE Medium openssl-3.0.2 0.91970 false
CVE-2023-0286 Anchore CVE High openssl-3.0.2 0.89079 N/A
CVE-2022-3602 Anchore CVE High openssl-3.0.2 0.85032 N/A
CVE-2022-2068 Anchore CVE Critical openssl-3.0.2 0.73985 N/A
CVE-2022-36944 Anchore CVE Critical scala-collection-compat_2.12-2.1.1 0.70885 N/A
CVE-2022-1292 Anchore CVE Critical openssl-3.0.2 0.70186 N/A
CVE-2023-26048 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.41170 false
CVE-2023-26048 Twistlock CVE Medium org.eclipse.jetty_jetty-server-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-xml-9.4.43.v20210629 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-servlets-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-http-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-servlet-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-io-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-plus-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-proxy-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-client-9.4.43.v20210629 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-client-9.4.48.v20220622 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-http-9.4.43.v20210629 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-io-9.4.43.v20210629 0.41170 false
CVE-2023-26048 Anchore CVE Medium jetty-webapp-9.4.43.v20210629 0.41170 false
CVE-2018-21234 Anchore CVE Critical hive-service-rpc-3.1.2 0.25246 N/A
CVE-2022-3786 Anchore CVE High openssl-3.0.2 0.19266 N/A
CVE-2022-3358 Anchore CVE High openssl-3.0.2 0.15503 N/A
CVE-2023-26031 Anchore CVE High hadoop-yarn-client-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-mapreduce-client-core-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-annotations-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-mapreduce-client-common-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-yarn-common-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-yarn-api-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-client-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-common-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-client-api-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-hdfs-client-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-mapreduce-client-jobclient-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-auth-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-yarn-server-web-proxy-3.3.2 0.12692 false
CVE-2023-26031 Anchore CVE High hadoop-client-runtime-3.3.2 0.12692 false
CVE-2024-28085 Anchore CVE Low util-linux-2.37.2 0.11480 false
CVE-2007-1100 Anchore CVE High pickle-1.2 0.07632 N/A
CVE-2024-5535 Anchore CVE Critical openssl-3.0.2 0.05152 false
CVE-2023-40167 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.03921 false
CVE-2023-40167 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.03921 false
CVE-2023-40167 Twistlock CVE Medium org.eclipse.jetty_jetty-http-9.4.43.v20210629 0.03921 false
CVE-2023-40167 Twistlock CVE Medium org.eclipse.jetty_jetty-http-9.4.48.v20220622 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-server-9.4.48.v20220622 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-client-9.4.48.v20220622 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-io-9.4.43.v20210629 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-webapp-9.4.43.v20210629 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-plus-9.4.48.v20220622 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-proxy-9.4.48.v20220622 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-servlets-9.4.48.v20220622 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-servlet-9.4.48.v20220622 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-client-9.4.43.v20210629 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-xml-9.4.43.v20210629 0.03921 false
CVE-2023-40167 Anchore CVE Medium jetty-io-9.4.48.v20220622 0.03921 false
CVE-2018-10237 Twistlock CVE Medium com.google.guava_guava-14.0.1 0.03259 false
CVE-2022-25168 Twistlock CVE Critical org.apache.hadoop_hadoop-common-3.3.2 0.02753 N/A
CVE-2022-25647 Twistlock CVE High gson-2.2.4 0.02149 N/A
CVE-2022-25647 Anchore CVE High gson-2.2.4 0.02149 N/A
CVE-2024-2511 Anchore CVE Medium openssl-3.0.2 0.02078 false
CVE-2023-5363 Anchore CVE High openssl-3.0.2 0.02052 false
CVE-2023-6129 Anchore CVE Medium openssl-3.0.2 0.01861 false
CVE-2019-10202 Twistlock CVE Critical jackson-mapper-asl-1.9.13 0.01830 N/A
CVE-2020-13949 Twistlock CVE High libthrift-0.12.0 0.01535 N/A
CVE-2023-4807 Anchore CVE High openssl-3.0.2 0.01436 false
CVE-2022-2048 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.01374 N/A
CVE-2022-2048 Anchore CVE High jetty-xml-9.4.43.v20210629 0.01374 N/A
CVE-2022-2048 Anchore CVE High jetty-webapp-9.4.43.v20210629 0.01374 N/A
CVE-2022-2048 Anchore CVE High jetty-client-9.4.43.v20210629 0.01374 N/A
CVE-2022-2048 Anchore CVE High jetty-io-9.4.43.v20210629 0.01374 N/A
CVE-2022-2048 Anchore CVE High jetty-http-9.4.43.v20210629 0.01374 N/A
CVE-2024-47561 Twistlock CVE Critical org.apache.avro_avro-1.11.0 0.01273 false
CVE-2024-47561 Twistlock CVE Critical org.apache.avro_avro-1.7.7 0.01273 false
CVE-2022-2047 Twistlock CVE Low org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.01225 N/A
CVE-2022-2047 Twistlock CVE Low org.eclipse.jetty_jetty-http-9.4.43.v20210629 0.01225 N/A
CVE-2022-2047 Anchore CVE Low jetty-client-9.4.43.v20210629 0.01225 N/A
CVE-2022-2047 Anchore CVE Low jetty-webapp-9.4.43.v20210629 0.01225 N/A
CVE-2022-2047 Anchore CVE Low jetty-xml-9.4.43.v20210629 0.01225 N/A
CVE-2022-2047 Anchore CVE Low jetty-io-9.4.43.v20210629 0.01225 N/A
CVE-2023-36478 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.01120 false
CVE-2023-36478 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-util-ajax-9.4.43.v20210629 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-proxy-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-xml-9.4.43.v20210629 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-webapp-9.4.43.v20210629 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-security-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-client-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-util-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-continuation-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-plus-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-http-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-client-9.4.43.v20210629 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-servlets-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-servlet-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-util-9.4.43.v20210629 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-io-9.4.43.v20210629 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-server-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-io-9.4.48.v20220622 0.01120 false
CVE-2023-36478 Anchore CVE High jetty-http-9.4.43.v20210629 0.01120 false
CVE-2025-0938 Anchore CVE Medium python-3.10.12 0.01039 false
CVE-2023-0401 Anchore CVE High openssl-3.0.2 0.00945 N/A
CVE-2024-23945 Twistlock CVE High org.apache.spark_spark-hive-thriftserver_2.12-3.3.4 0.00943 false
CVE-2023-0464 Anchore CVE High openssl-3.0.2 0.00875 false
CVE-2023-36479 Twistlock CVE Low org.eclipse.jetty_jetty-servlets-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Twistlock CVE Low org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Twistlock CVE Low org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-io-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-plus-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-io-9.4.43.v20210629 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-webapp-9.4.43.v20210629 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-http-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-proxy-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-server-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-servlet-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-client-9.4.48.v20220622 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-http-9.4.43.v20210629 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-client-9.4.43.v20210629 0.00862 false
CVE-2023-36479 Anchore CVE Low jetty-xml-9.4.43.v20210629 0.00862 false
CVE-2023-3446 Anchore CVE Medium openssl-3.0.2 0.00785 false
CVE-2023-0216 Anchore CVE High openssl-3.0.2 0.00778 N/A
CVE-2024-6232 Anchore CVE High python-3.10.12 0.00776 false
CVE-2022-40152 Twistlock CVE Medium com.fasterxml.woodstox_woodstox-core-5.3.0 0.00702 N/A
CVE-2019-0205 Twistlock CVE High libthrift-0.12.0 0.00698 N/A
CVE-2022-1271 Anchore CVE High xz-1.9 0.00672 N/A
CVE-2023-0466 Anchore CVE Medium openssl-3.0.2 0.00666 false
CVE-2023-34453 Twistlock CVE Medium org.xerial.snappy_snappy-java-1.1.8.4 0.00588 false
CVE-2019-10172 Twistlock CVE High jackson-mapper-asl-1.9.13 0.00570 N/A
CVE-2022-2097 Anchore CVE Medium openssl-3.0.2 0.00553 N/A
CVE-2018-1330 Twistlock CVE High org.apache.mesos_mesos-1.4.3 0.00544 N/A
CVE-2023-6237 Anchore CVE Medium openssl-3.0.2 0.00539 false
CVE-2024-4032 Anchore CVE High python-3.10.12 0.00526 false
CVE-2020-36518 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.11.4 0.00490 N/A
CVE-2021-22569 Twistlock CVE High com.google.protobuf_protobuf-java-3.3.0 0.00479 N/A
CVE-2021-22569 Twistlock CVE High com.google.protobuf_protobuf-java-3.7.1 0.00479 N/A
CVE-2021-22569 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0 0.00479 N/A
CVE-2024-6119 Anchore CVE High openssl-3.0.2 0.00456 false
CVE-2023-0217 Anchore CVE High openssl-3.0.2 0.00449 N/A
CVE-2024-26308 Twistlock CVE Medium org.apache.commons_commons-compress-1.21 0.00430 false
CVE-2023-0465 Anchore CVE Medium openssl-3.0.2 0.00421 false
CVE-2024-9143 Anchore CVE Medium openssl-3.0.2 0.00416 false
CVE-2023-34462 Twistlock CVE Medium io.netty_netty-handler-4.1.74.Final 0.00416 false
CVE-2022-4203 Anchore CVE Medium openssl-3.0.2 0.00404 N/A
CVE-2024-0397 Anchore CVE High python-3.10.12 0.00393 false
CVE-2015-4035 Anchore CVE High xz-1.9 0.00387 N/A
CVE-2024-29133 Twistlock CVE Medium org.apache.commons_commons-configuration2-2.1.1 0.00375 false
CVE-2023-22946 Twistlock CVE Critical pyspark-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-kubernetes_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-yarn_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-mllib-local_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-kvstore_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-network-shuffle_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-tags_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-tags_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-catalyst_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-mllib_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-repl_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-sql_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-sketch_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-hive_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-network-common_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-graphx_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-hive-thriftserver_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-launcher_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-streaming_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-mesos_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-unsafe_2.12-3.3.4 0.00370 false
CVE-2023-22946 Anchore CVE Critical spark-core_2.12-3.3.4 0.00370 false
CVE-2023-0215 Anchore CVE High openssl-3.0.2 0.00346 N/A
CVE-2023-34455 Twistlock CVE High org.xerial.snappy_snappy-java-1.1.8.4 0.00339 false
CVE-2024-7592 Anchore CVE High python-3.10.12 0.00325 false
CVE-2023-26049 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.00322 false
CVE-2023-26049 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.00322 false
CVE-2023-26049 Twistlock CVE Low org.eclipse.jetty_jetty-server-9.4.48.v20220622 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-http-9.4.43.v20210629 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-plus-9.4.48.v20220622 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-webapp-9.4.43.v20210629 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-servlets-9.4.48.v20220622 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-servlet-9.4.48.v20220622 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-io-9.4.48.v20220622 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-client-9.4.48.v20220622 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-io-9.4.43.v20210629 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-client-9.4.43.v20210629 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-xml-9.4.43.v20210629 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-proxy-9.4.48.v20220622 0.00322 false
CVE-2023-26049 Anchore CVE Medium jetty-http-9.4.48.v20220622 0.00322 false
CVE-2022-40897 Twistlock CVE Medium setuptools-59.6.0 Code path is deprecated. 0.00318 N/A
CVE-2022-42003 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.11.4 0.00303 N/A
CVE-2022-42003 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.13.0 0.00303 N/A
CVE-2024-22201 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.00301 false
CVE-2024-22201 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.00301 false
CVE-2019-0210 Twistlock CVE High libthrift-0.12.0 0.00297 N/A
CVE-2019-0210 Anchore CVE High libthrift-0.12.0 0.00297 N/A
CVE-2023-40217 Anchore CVE Medium python-3.10.12 0.00284 false
CVE-2023-3817 Anchore CVE Medium openssl-3.0.2 0.00264 false
CVE-2023-3635 Twistlock CVE Medium com.squareup.okio_okio-1.14.0 0.00247 false
CVE-2023-3635 Twistlock CVE Medium com.squareup.okio_okio-1.6.0 0.00247 false
CVE-2024-9823 Twistlock CVE Medium org.eclipse.jetty_jetty-servlets-9.4.48.v20220622 0.00244 false
CVE-2022-1473 Anchore CVE High openssl-3.0.2 0.00238 N/A
CVE-2022-4304 Anchore CVE Medium openssl-3.0.2 0.00237 N/A
CVE-2021-3995 Anchore CVE Medium util-linux-2.37.2 0.00233 N/A
CVE-2021-3996 Anchore CVE Medium util-linux-2.37.2 0.00232 N/A
CVE-2024-6345 Twistlock CVE High setuptools-59.6.0 Most users have migrated off of the code paths that are affected. The affected code paths are actively deprecated and planned for turn down. Only specialized and legacy workflows are affected. Use recommended installers pip, uv, build, system package managers to install all packages from trusted indexes. If working with untrusted content in private indexes, consider scanning for malicious code in the package index pages. 0.00227 false
CVE-2022-42004 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.13.0 0.00219 N/A
CVE-2022-42004 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.11.4 0.00219 N/A
CVE-2024-0727 Anchore CVE Medium openssl-3.0.2 0.00217 false
CVE-2024-36114 Twistlock CVE High io.airlift_aircompressor-0.21 0.00209 false
CVE-2023-34454 Twistlock CVE Medium org.xerial.snappy_snappy-java-1.1.8.4 0.00201 false
CVE-2024-11168 Anchore CVE Medium python-3.10.12 0.00198 false
CVE-2022-40898 Twistlock CVE High wheel-0.37.1 0.00196 N/A
CVE-2022-3996 Anchore CVE High openssl-3.0.2 0.00185 N/A
CVE-2025-48734 Twistlock CVE Low commons-beanutils_commons-beanutils-1.9.4 0.00182 false
CVE-2021-37533 Twistlock CVE Medium commons-net_commons-net-3.6 0.00177 N/A
CVE-2024-0450 Anchore CVE Medium python-3.10.12 0.00173 false
CVE-2025-1795 Anchore CVE Low python-3.10.12 0.00167 false
CVE-2024-4741 Anchore CVE High openssl-3.0.2 0.00167 false
CVE-2022-38752 Twistlock CVE Medium org.yaml_snakeyaml-1.31 0.00167 N/A
CVE-2024-8184 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.00157 false
CVE-2024-8184 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Twistlock CVE Medium org.eclipse.jetty_jetty-server-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-client-9.4.43.v20210629 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-client-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-servlet-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-io-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-plus-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-webapp-9.4.43.v20210629 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-http-9.4.43.v20210629 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-io-9.4.43.v20210629 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-http-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-proxy-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-servlets-9.4.48.v20220622 0.00157 false
CVE-2024-8184 Anchore CVE Medium jetty-xml-9.4.43.v20210629 0.00157 false
CVE-2024-7254 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0 0.00150 false
CVE-2024-7254 Twistlock CVE High com.google.protobuf_protobuf-java-3.3.0 0.00150 false
CVE-2024-7254 Twistlock CVE High com.google.protobuf_protobuf-java-3.7.1 0.00150 false
CVE-2024-29131 Twistlock CVE Medium org.apache.commons_commons-configuration2-2.1.1 0.00149 false
CVE-2023-41900 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.00143 false
CVE-2023-41900 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-proxy-9.4.48.v20220622 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-xml-9.4.43.v20210629 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-client-9.4.48.v20220622 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-servlet-9.4.48.v20220622 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-servlets-9.4.48.v20220622 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-io-9.4.48.v20220622 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-io-9.4.43.v20210629 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-plus-9.4.48.v20220622 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-webapp-9.4.43.v20210629 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-http-9.4.43.v20210629 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-client-9.4.43.v20210629 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-http-9.4.48.v20220622 0.00143 false
CVE-2023-41900 Anchore CVE Medium jetty-server-9.4.48.v20220622 0.00143 false
CVE-2021-22570 Twistlock CVE High com.google.protobuf_protobuf-java-3.3.0 0.00142 N/A
CVE-2021-22570 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0 0.00142 N/A
CVE-2021-22570 Twistlock CVE High com.google.protobuf_protobuf-java-3.7.1 0.00142 N/A
CVE-2023-2975 Anchore CVE Medium openssl-3.0.2 0.00137 false
CVE-2025-47287 Twistlock CVE High tornado-6.4.2 0.00136 false
CVE-2022-4450 Anchore CVE High openssl-3.0.2 0.00129 N/A
CVE-2022-1343 Anchore CVE Medium openssl-3.0.2 0.00127 N/A
CVE-2024-3220 Anchore CVE Low python-3.10.12 0.00122 false
CVE-2023-5678 Anchore CVE Medium openssl-3.0.2 0.00122 false
CVE-2025-47273 Twistlock CVE High setuptools-78.1.0 0.00120 false
CVE-2025-47273 Twistlock CVE High setuptools-59.6.0 0.00120 false
CVE-2024-23953 Twistlock CVE Medium org.apache.hive_hive-llap-common-2.3.9 0.00113 false
CVE-2024-6763 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.48.v20220622 0.00108 false
CVE-2024-6763 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.43.v20210629 0.00108 false
CVE-2024-6763 Twistlock CVE Medium org.eclipse.jetty_jetty-http-9.4.43.v20210629 0.00108 false
CVE-2024-6763 Twistlock CVE Medium org.eclipse.jetty_jetty-http-9.4.48.v20220622 0.00108 false
CVE-2025-25193 Twistlock CVE Medium io.netty_netty-common-4.1.74.Final 0.00103 false
CVE-2021-46877 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.11.4 0.00097 false
CVE-2021-46877 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.13.0 0.00097 false
CVE-2022-3509 Twistlock CVE High com.google.protobuf_protobuf-java-3.3.0 0.00096 N/A
CVE-2022-3509 Twistlock CVE High com.google.protobuf_protobuf-java-3.7.1 0.00096 N/A
CVE-2022-3509 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0 0.00096 N/A
CVE-2025-4517 Anchore CVE Critical python-3.10.12 0.00095 false
CVE-2024-6923 Anchore CVE Medium python-3.10.12 0.00089 false
CVE-2025-4138 Anchore CVE High python-3.10.12 0.00088 false
CVE-2024-8088 Anchore CVE High python-3.10.12 0.00087 false
CVE-2022-46751 Anchore CVE High ivy-2.5.1 0.00086 false
CVE-2023-27043 Anchore CVE Medium python-3.10.12 0.00085 false
CVE-2021-31684 Twistlock CVE High net.minidev_json-smart-1.3.2 0.00082 N/A
CVE-2023-52428 Twistlock CVE High com.nimbusds_nimbus-jose-jwt-9.8.1 0.00080 false
CVE-2024-4603 Anchore CVE Medium openssl-3.0.2 0.00079 false
CVE-2025-4330 Anchore CVE High python-3.10.12 0.00078 false
CVE-2022-41854 Twistlock CVE Medium org.yaml_snakeyaml-1.31 0.00076 N/A
CVE-2023-6597 Anchore CVE High python-3.10.12 0.00075 false
CVE-2023-43642 Twistlock CVE High org.xerial.snappy_snappy-java-1.1.8.4 0.00073 false
CVE-2022-3171 Twistlock CVE Medium com.google.protobuf_protobuf-java-3.3.0 0.00071 N/A
CVE-2022-3171 Twistlock CVE Medium com.google.protobuf_protobuf-java-3.7.1 0.00071 N/A
CVE-2022-3171 Twistlock CVE Medium com.google.protobuf_protobuf-java-2.5.0 0.00071 N/A
CVE-2024-12718 Anchore CVE Medium python-3.10.12 0.00063 false
CVE-2024-47081 Twistlock CVE Medium requests-2.32.3 0.00062 false
CVE-2025-4435 Anchore CVE High python-3.10.12 0.00059 false
CVE-2022-1434 Anchore CVE Medium openssl-3.0.2 0.00059 N/A
CVE-2022-3510 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0 0.00053 N/A
CVE-2022-3510 Twistlock CVE High com.google.protobuf_protobuf-java-3.7.1 0.00053 N/A
CVE-2022-3510 Twistlock CVE High com.google.protobuf_protobuf-java-3.3.0 0.00053 N/A
CVE-2025-6069 Anchore CVE Medium python-3.10.12 0.00052 false
CVE-2024-25638 Twistlock CVE High dnsjava_dnsjava-2.1.7 0.00048 false
CVE-2024-47554 Twistlock CVE High commons-io_commons-io-2.8.0 0.00046 false
CVE-2024-47554 Twistlock CVE High commons-io_commons-io-2.11.0 0.00046 false
CVE-2023-1255 Anchore CVE Medium openssl-3.0.2 0.00046 false
CVE-2024-13176 Anchore CVE Medium openssl-3.0.2 0.00045 false
CVE-2023-39410 Twistlock CVE High avro-1.10.2 0.00045 false
CVE-2023-39410 Twistlock CVE High org.apache.avro_avro-1.7.7 0.00045 false
CVE-2023-39410 Twistlock CVE High org.apache.avro_avro-1.11.0 0.00045 false
CVE-2023-39410 Anchore CVE High avro-ipc-1.11.0 0.00045 false
CVE-2023-39410 Anchore CVE High avro-mapred-1.11.0 0.00045 false
CVE-2022-46337 Anchore CVE Critical derby-10.14.2.0 0.00045 false
CVE-2025-43859 Twistlock CVE Critical h11-0.14.0 0.00044 false
CVE-2024-47535 Twistlock CVE Medium io.netty_netty-common-4.1.74.Final 0.00042 false
CVE-2024-23944 Twistlock CVE Medium org.apache.zookeeper_zookeeper-3.6.2 0.00042 false
CVE-2024-23944 Anchore CVE Medium zookeeper-jute-3.6.2 0.00042 false
CVE-2023-2976 Twistlock CVE High com.google.guava_guava-14.0.1 0.00041 false
CVE-2023-2976 Twistlock CVE High com.google.guava_guava-30.1.1-jre 0.00041 false
CVE-2024-23454 Twistlock CVE Low org.apache.hadoop_hadoop-common-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-mapreduce-client-common-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-hdfs-client-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-shaded-guava-1.1.1 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-yarn-server-web-proxy-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-shaded-guava-1.1.1 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-shaded-protobuf_3_7-1.1.1 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-yarn-common-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-yarn-client-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-yarn-api-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-auth-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-client-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-mapreduce-client-core-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-client-runtime-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-mapreduce-client-jobclient-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-client-api-3.3.2 0.00040 false
CVE-2024-23454 Anchore CVE Medium hadoop-annotations-3.3.2 0.00040 false
CVE-2023-5752 Twistlock CVE Low pip-22.0.2 Only users using Mercurial VCS functionality with untrusted inputs are affected. 0.00040 false
CVE-2024-13009 Twistlock CVE High org.eclipse.jetty_jetty-server-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-client-9.4.43.v20210629 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-plus-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-io-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-http-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-security-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-servlet-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-http-9.4.43.v20210629 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-io-9.4.43.v20210629 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-continuation-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-util-9.4.43.v20210629 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-servlets-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-webapp-9.4.43.v20210629 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-xml-9.4.43.v20210629 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-util-ajax-9.4.43.v20210629 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-client-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-util-9.4.48.v20220622 0.00039 false
CVE-2024-13009 Anchore CVE High jetty-proxy-9.4.48.v20220622 0.00039 false
CVE-2024-9287 Anchore CVE High python-3.10.12 0.00038 false
CVE-2024-50602 Anchore CVE Medium python-3.10.12 0.00037 false
CVE-2023-0833 Twistlock CVE Medium com.squareup.okhttp3_okhttp-3.12.12 0.00037 false
CVE-2023-0833 Anchore CVE Medium okhttp-2.7.5 0.00037 false
CVE-2023-0833 Anchore CVE Medium okhttp-3.12.12 0.00037 false
CVE-2023-44981 Twistlock CVE Critical org.apache.zookeeper_zookeeper-3.6.2 0.00025 false
CVE-2023-44981 Anchore CVE Critical zookeeper-jute-3.6.2 0.00025 false
CVE-2022-0563 Anchore CVE Medium util-linux-2.37.2 0.00025 N/A
CVE-2024-29869 Twistlock CVE Medium org.apache.hive_hive-exec-2.3.9 0.00021 false
CVE-2025-47436 Anchore CVE Medium orc-mapreduce-1.7.10 0.00020 false
CVE-2025-47436 Anchore CVE Medium orc-core-1.7.10 0.00020 false
CVE-2025-47436 Anchore CVE Medium orc-shims-1.7.10 0.00020 false
CVE-2025-4516 Anchore CVE Medium python-3.10.12 0.00020 false
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.13.4.2 0.00015 false
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.11.4 0.00015 false
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.13.0 0.00015 false
CVE-2024-25710 Twistlock CVE Medium org.apache.commons_commons-compress-1.21 0.00012 false
CVE-2025-30167 Twistlock CVE High jupyter_core-5.7.2 0.00011 false
CVE-2023-1370 Twistlock CVE High net.minidev_json-smart-1.3.2 0.00011 N/A
CVE-2025-50181 Twistlock CVE Medium urllib3-1.26.20 0.00010 false
CVE-2025-50182 Twistlock CVE Medium urllib3-1.26.20 0.00009 false
CVE-2020-8908 Twistlock CVE Low com.google.guava_guava-30.1.1-jre 0.00008 N/A
CVE-2020-8908 Twistlock CVE Low com.google.guava_guava-14.0.1 0.00008 N/A
CVE-2025-49128 Twistlock CVE Medium com.fasterxml.jackson.core_jackson-core-2.11.4 0.00005 false
GHSA-58qw-p7qm-5rvh Twistlock CVE Low org.eclipse.jetty_jetty-xml-9.4.43.v20210629 None false
GHSA-58qw-p7qm-5rvh Anchore CVE Low jetty-xml-9.4.43.v20210629 None false
fbe3c91b110eabf67665190b181ac77d Anchore Compliance Critical N/A N/A
PRISMA-2023-0067 Twistlock CVE High com.fasterxml.jackson.core_jackson-core-2.11.4 N/A N/A
PRISMA-2023-0067 Twistlock CVE High com.fasterxml.jackson.core_jackson-core-2.13.4 N/A N/A
PRISMA-2023-0067 Twistlock CVE High com.fasterxml.jackson.core_jackson-core-2.13.0 N/A N/A
PRISMA-2023-0024 Twistlock CVE High aiohttp-3.11.16 N/A N/A
PRISMA-2023-0024 Twistlock CVE High aiohttp-3.12.13 N/A N/A
PRISMA-2022-0404 Twistlock CVE Medium wheel-0.37.1 N/A N/A
PRISMA-2022-0168 Twistlock CVE High pip-22.0.2 N/A N/A
PRISMA-2022-0168 Twistlock CVE High pip-25.1.1 N/A N/A
PRISMA-2021-0055 Twistlock CVE Low commons-codec_commons-codec-1.11 N/A N/A
GHSA-xq3w-v528-46rv Anchore CVE Medium netty-common-4.1.74.Final N/A N/A
GHSA-xjp4-hw94-mvp5 Anchore CVE Medium commons-configuration2-2.1.1 N/A N/A
GHSA-wxr5-93ph-8wr9 Anchore CVE High commons-beanutils-1.9.4 N/A N/A
GHSA-wrvw-hg22-4m67 Anchore CVE High protobuf-java-3.3.0 N/A N/A
GHSA-wrvw-hg22-4m67 Anchore CVE High protobuf-java-2.5.0 N/A N/A
GHSA-wrvw-hg22-4m67 Anchore CVE High protobuf-java-3.7.1 N/A N/A
GHSA-wf8f-6423-gfxg Anchore CVE Medium jackson-core-2.11.4 N/A N/A
GHSA-w37g-rhq8-7m4j Anchore CVE Medium snakeyaml-1.31 N/A N/A
GHSA-w33c-445m-f8w7 Anchore CVE Medium okio-1.14.0 N/A N/A
GHSA-w33c-445m-f8w7 Anchore CVE Medium okio-1.6.0 N/A N/A
GHSA-vqfr-h8mv-ghfj Anchore CVE Critical h11-0.14.0 N/A N/A
GHSA-rj7p-rfgp-852x Anchore CVE High libthrift-0.12.0 N/A N/A
GHSA-rhrv-645h-fjfh Anchore CVE High avro-1.10.2 N/A N/A
GHSA-rhrv-645h-fjfh Anchore CVE High avro-1.11.0 N/A N/A
GHSA-rhrv-645h-fjfh Anchore CVE High avro-1.7.7 N/A N/A
GHSA-rgv9-q543-rqg4 Anchore CVE High jackson-databind-2.11.4 N/A N/A
GHSA-rgv9-q543-rqg4 Anchore CVE High jackson-databind-2.13.0 N/A N/A
GHSA-r9hx-vwmv-q579 Anchore CVE High setuptools-59.6.0 N/A N/A
GHSA-r9hx-vwmv-q579 Anchore CVE High setuptools-59.6.0 N/A N/A
GHSA-r978-9m6m-6gm6 Anchore CVE Medium zookeeper-3.6.2 N/A N/A
GHSA-r7pg-v2c8-mfg3 Anchore CVE Critical avro-1.7.7 N/A N/A
GHSA-r7pg-v2c8-mfg3 Anchore CVE Critical avro-1.11.0 N/A N/A
GHSA-qwmp-2cf2-g9g6 Anchore CVE High wheel-0.37.1 N/A N/A
GHSA-qw69-rqj8-6qw8 Anchore CVE Medium jetty-server-9.4.48.v20220622 N/A N/A
GHSA-qh8g-58pp-2wxh Anchore CVE Medium jetty-http-9.4.43.v20210629 N/A N/A
GHSA-qh8g-58pp-2wxh Anchore CVE Medium jetty-http-9.4.48.v20220622 N/A N/A
GHSA-qcwq-55hx-v3vh Anchore CVE High snappy-java-1.1.8.4 N/A N/A
GHSA-q4rv-gq96-w7c5 Anchore CVE High jetty-server-9.4.48.v20220622 N/A N/A
GHSA-pqr6-cmr2-h8hf Anchore CVE Medium snappy-java-1.1.8.4 N/A N/A
GHSA-pq67-6m6q-mj2v Anchore CVE Medium urllib3-1.26.20 N/A N/A
GHSA-p953-3j66-hg45 Anchore CVE Medium hive-llap-common-2.3.9 N/A N/A
GHSA-p26g-97m4-6q7c Anchore CVE Low jetty-server-9.4.48.v20220622 N/A N/A
GHSA-mvr2-9pj6-7w5j Anchore CVE Medium guava-14.0.1 N/A N/A
GHSA-mvr2-9pj6-7w5j Anchore CVE Medium guava-14.0.1 N/A N/A
GHSA-mq26-g339-26xf Anchore CVE Medium pip-22.0.2 N/A N/A
GHSA-mjmj-j48q-9wg2 Anchore CVE High snakeyaml-1.31 N/A N/A
GHSA-jjjh-jjxp-wpff Anchore CVE High jackson-databind-2.11.4 N/A N/A
GHSA-jjjh-jjxp-wpff Anchore CVE High jackson-databind-2.13.0 N/A N/A
GHSA-j26w-f9rq-mr2q Anchore CVE Medium jetty-servlets-9.4.48.v20220622 N/A N/A
GHSA-hmr7-m48g-48f6 Anchore CVE Medium jetty-http-9.4.48.v20220622 N/A N/A
GHSA-hmr7-m48g-48f6 Anchore CVE Medium jetty-http-9.4.43.v20210629 N/A N/A
GHSA-h4h5-3hr4-j3g2 Anchore CVE Medium protobuf-java-3.7.1 N/A N/A
GHSA-h4h5-3hr4-j3g2 Anchore CVE Medium protobuf-java-2.5.0 N/A N/A
GHSA-h4h5-3hr4-j3g2 Anchore CVE Medium protobuf-java-3.3.0 N/A N/A
GHSA-gvpg-vgmx-xg6w Anchore CVE High nimbus-jose-jwt-9.8.1 N/A N/A
GHSA-g8m5-722r-8whq Anchore CVE Medium jetty-server-9.4.48.v20220622 N/A N/A
GHSA-g5ww-5jh7-63cx Anchore CVE High protobuf-java-2.5.0 N/A N/A
GHSA-g5ww-5jh7-63cx Anchore CVE High protobuf-java-3.3.0 N/A N/A
GHSA-g5ww-5jh7-63cx Anchore CVE High protobuf-java-3.7.1 N/A N/A
GHSA-g2fg-mr77-6vrm Anchore CVE High libthrift-0.12.0 N/A N/A
GHSA-fjpj-2g6w-x25r Anchore CVE Medium snappy-java-1.1.8.4 N/A N/A
GHSA-fg2v-w576-w4v3 Anchore CVE High json-smart-1.3.2 N/A N/A
GHSA-f5fw-25gw-5m92 Anchore CVE Low hadoop-common-3.3.2 N/A N/A
GHSA-cx63-2mw6-8hw5 Anchore CVE High setuptools-59.6.0 N/A N/A
GHSA-cx63-2mw6-8hw5 Anchore CVE High setuptools-59.6.0 N/A N/A
GHSA-cj7v-27pg-wf7q Anchore CVE Low jetty-http-9.4.43.v20210629 N/A N/A
GHSA-cgp8-4m63-fhh5 Anchore CVE Medium commons-net-3.6 N/A N/A
GHSA-cfxw-4h78-h7fw Anchore CVE High dnsjava-2.1.7 N/A N/A
GHSA-c476-j253-5rgq Anchore CVE Medium hive-exec-2.3.9 N/A N/A
GHSA-9w3m-gqgf-c4p9 Anchore CVE Medium snakeyaml-1.31 N/A N/A
GHSA-9w38-p64v-xpmv Anchore CVE Medium commons-configuration2-2.1.1 N/A N/A
GHSA-9hjg-9r4m-mvj7 Anchore CVE Medium requests-2.32.3 N/A N/A
GHSA-973x-65j7-xcf4 Anchore CVE High aircompressor-0.21 N/A N/A
GHSA-95q3-pppp-r683 Anchore CVE High mesos-1.4.3 N/A N/A
GHSA-8wm5-8h9c-47pc Anchore CVE Critical hadoop-common-3.3.2 N/A N/A
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-30.1.1-jre N/A N/A
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-30.1.1-jre N/A N/A
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-14.0.1 N/A N/A
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-14.0.1 N/A N/A
GHSA-7cx3-6m66-7c5m Anchore CVE High tornado-6.4.2 N/A N/A
GHSA-78wr-2p64-hpwj Anchore CVE High commons-io-2.11.0 N/A N/A
GHSA-78wr-2p64-hpwj Anchore CVE High commons-io-2.8.0 N/A N/A
GHSA-77rm-9x9h-xj3g Anchore CVE High protobuf-java-2.5.0 N/A N/A
GHSA-77rm-9x9h-xj3g Anchore CVE High protobuf-java-3.7.1 N/A N/A
GHSA-77rm-9x9h-xj3g Anchore CVE High protobuf-java-3.3.0 N/A N/A
GHSA-77pm-w3hx-f8mj Anchore CVE High spark-hive-thriftserver_2.12-3.3.4 N/A N/A
GHSA-735f-pc8j-v9w8 Anchore CVE High protobuf-java-3.3.0 N/A N/A
GHSA-735f-pc8j-v9w8 Anchore CVE High protobuf-java-2.5.0 N/A N/A
GHSA-735f-pc8j-v9w8 Anchore CVE High protobuf-java-3.7.1 N/A N/A
GHSA-7286-pgfv-vxvh Anchore CVE Critical zookeeper-3.6.2 N/A N/A
GHSA-6mjq-h674-j845 Anchore CVE Medium netty-handler-4.1.74.Final N/A N/A
GHSA-5rjg-fvgr-3xxf Anchore CVE High setuptools-59.6.0 N/A N/A
GHSA-5rjg-fvgr-3xxf Anchore CVE High setuptools-78.1.0 N/A N/A
GHSA-5rjg-fvgr-3xxf Anchore CVE High setuptools-59.6.0 N/A N/A
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-14.0.1 N/A N/A
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-14.0.1 N/A N/A
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-30.1.1-jre N/A N/A
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-30.1.1-jre N/A N/A
GHSA-59j4-wjwp-mw9m Anchore CVE High velocity-1.5 N/A N/A
GHSA-57j2-w4cx-62h2 Anchore CVE High jackson-databind-2.13.0 N/A N/A
GHSA-57j2-w4cx-62h2 Anchore CVE High jackson-databind-2.11.4 N/A N/A
GHSA-55g7-9cwv-5qfv Anchore CVE High snappy-java-1.1.8.4 N/A N/A
GHSA-4gg5-vx3j-xwc7 Anchore CVE High protobuf-java-3.7.1 N/A N/A
GHSA-4gg5-vx3j-xwc7 Anchore CVE High protobuf-java-2.5.0 N/A N/A
GHSA-4gg5-vx3j-xwc7 Anchore CVE High protobuf-java-3.3.0 N/A N/A
GHSA-4g9r-vxhx-9pgx Anchore CVE Medium commons-compress-1.21 N/A N/A
GHSA-4g9r-vxhx-9pgx Anchore CVE Medium commons-compress-1.21 N/A N/A
GHSA-493p-pfq6-5258 Anchore CVE High json-smart-1.3.2 N/A N/A
GHSA-48p4-8xcf-vxj5 Anchore CVE Medium urllib3-1.26.20 N/A N/A
GHSA-4265-ccf5-phj5 Anchore CVE Medium commons-compress-1.21 N/A N/A
GHSA-4265-ccf5-phj5 Anchore CVE Medium commons-compress-1.21 N/A N/A
GHSA-3x8x-79m2-3w2w Anchore CVE High jackson-databind-2.11.4 N/A N/A
GHSA-3x8x-79m2-3w2w Anchore CVE High jackson-databind-2.13.0 N/A N/A
GHSA-3gh6-v5v9-6v9j Anchore CVE Low jetty-servlets-9.4.48.v20220622 N/A N/A
GHSA-3f7h-mf4q-vrm4 Anchore CVE Medium woodstox-core-5.3.0 N/A N/A
GHSA-389x-839f-4rhx Anchore CVE Medium netty-common-4.1.74.Final N/A N/A
GHSA-33p9-3p43-82vq Anchore CVE High jupyter-core-5.7.2 N/A N/A
8e163263cda4bd745af2e34598d058fe Anchore Compliance Critical N/A N/A
84efd73217868bfa299d48646db02ffb Anchore Compliance Critical N/A N/A
49dd8fc1f0f88eb007cdef4e305130d0 Anchore Compliance Critical N/A N/A
41005d4717e971a09f24bca264e037f6 Anchore Compliance Critical N/A N/A
03d8818ad9057a73338df2519447cb06 Anchore Compliance Critical N/A N/A

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=ccj2-a3im/datahub/datahub-actions&tag=v0.2.1&branch=master

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Verification label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by CHORE_TOKEN
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information