UNCLASSIFIED - NO CUI

Skip to content

chore(findings): cloudfit/cfs/cfs-logrhythmwatcher

Summary

cloudfit/cfs/cfs-logrhythmwatcher has 15 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=cloudfit/cfs/cfs-logrhythmwatcher&tag=0.1.0&branch=master

EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.

id source severity package impact workaround epss_score kev
CVE-2022-41032 Twistlock CVE High .net-core-3.1.12 0.16693 false
CVE-2021-31204 Twistlock CVE Medium .net-core-3.1.12 0.08688 false
CVE-2022-23267 Twistlock CVE Medium .net-core-3.1.12 0.06422 false
CVE-2022-29145 Twistlock CVE Medium .net-core-3.1.12 0.04834 false
CVE-2021-31957 Twistlock CVE Medium .net-core-3.1.12 0.03841 false
CVE-2022-24464 Twistlock CVE Medium .net-core-3.1.12 0.02952 false
CVE-2021-26423 Twistlock CVE Medium .net-core-3.1.12 0.02420 false
CVE-2022-29117 Twistlock CVE Medium .net-core-3.1.12 0.02187 false
CVE-2021-26701 Twistlock CVE High .net-core-3.1.12 0.01745 false
CVE-2022-38013 Twistlock CVE Low .net-core-3.1.12 0.01034 false
CVE-2022-34716 Twistlock CVE Low .net-core-3.1.12 0.00963 false
CVE-2021-34485 Twistlock CVE Low .net-core-3.1.12 0.00958 false
CVE-2022-30184 Twistlock CVE Medium .net-core-3.1.12 0.00528 false
CVE-2020-8927 Twistlock CVE Medium .net-core-3.1.12 0.00420 false
CVE-2022-24512 Twistlock CVE Medium .net-core-3.1.12 0.00247 false

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=cloudfit/cfs/cfs-logrhythmwatcher&tag=0.1.0&branch=master

Tasks

Contributor:

  • Apply the StatusReview label to this issue for a merge request review and wait for feedback

OR

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue for a VAT justifications review and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Review or Verification label will be removed and the issue will be sent back to To-Do. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Review or Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by CHORE_TOKEN
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information