UNCLASSIFIED - NO CUI

Skip to content

chore(findings): frontiertechnology/cortex/dbmigration-init

Summary

frontiertechnology/cortex/dbmigration-init has 40 new findings discovered during continuous monitoring.

id source severity package
CVE-2021-27293 Anchore CVE High RestSharp-106.10.1
CVE-2021-21287 Anchore CVE High Minio-3.1.13
CVE-2018-1000538 Anchore CVE High Minio-3.1.13
CVE-2021-21390 Anchore CVE Medium Minio-3.1.13
CVE-2020-11012 Anchore CVE High Minio-3.1.13
CVE-2021-21362 Anchore CVE Medium Minio-3.1.13
CVE-2021-43858 Anchore CVE High Minio-3.1.13
CVE-2022-35919 Anchore CVE Low Minio-3.1.13
CVE-2022-42898 Twistlock CVE Critical krb5-libs-1.18.2-21.el8
CVE-2022-45061 Twistlock CVE Medium python3-libs-3.6.8-48.el8_7
CVE-2022-45061 Twistlock CVE Medium platform-python-3.6.8-48.el8_7
CVE-2022-36227 Twistlock CVE Low libarchive-3.3.3-4.el8
CVE-2007-4559 Anchore CVE Medium platform-python-3.6.8-48.el8_7
CVE-2022-42898 Anchore CVE High krb5-libs-1.18.2-21.el8
CVE-2021-46848 Anchore CVE Medium libtasn1-4.13-3.el8
CVE-2022-43680 Anchore CVE Medium expat-2.2.5-10.el8
CVE-2022-45061 Anchore CVE Medium python3-libs-3.6.8-48.el8_7
CVE-2022-35737 Anchore CVE Medium sqlite-libs-3.26.0-16.el8_6
CVE-2022-45061 Anchore CVE Medium platform-python-3.6.8-48.el8_7
CVE-2007-4559 Anchore CVE Medium python3-libs-3.6.8-48.el8_7
CVE-2022-36227 Anchore CVE Low libarchive-3.3.3-4.el8
CVE-2022-42898 OSCAP Compliance Medium
CVE-2022-4285 Twistlock CVE Medium gdb-gdbserver-8.2-19.el8
CCE-86099-9 OSCAP Compliance Medium
CVE-2022-46908 Twistlock CVE Medium sqlite-libs-3.26.0-16.el8_6
CVE-2022-4285 Anchore CVE Medium gdb-gdbserver-8.2-19.el8
CVE-2022-4415 Twistlock CVE Medium systemd-239-68.el8
CVE-2022-4415 Twistlock CVE Medium systemd-pam-239-68.el8
CVE-2022-4415 Twistlock CVE Medium systemd-libs-239-68.el8
CVE-2022-43552 Twistlock CVE Low libcurl-7.61.1-25.el8
CVE-2022-43552 Twistlock CVE Low curl-7.61.1-25.el8
CVE-2022-43552 Anchore CVE Low curl-7.61.1-25.el8
CVE-2022-43552 Anchore CVE Low libcurl-7.61.1-25.el8
CVE-2022-4415 Anchore CVE Medium systemd-pam-239-68.el8
CVE-2022-4415 Anchore CVE Medium systemd-239-68.el8
CVE-2022-4415 Anchore CVE Medium systemd-libs-239-68.el8
CVE-2022-40897 Twistlock CVE High setuptools-39.2.0
CVE-2022-46908 Anchore CVE Medium sqlite-libs-3.26.0-16.el8_6
CVE-2022-35737 Twistlock CVE Medium sqlite-libs-3.26.0-16.el8_6
CVE-2022-23990 Twistlock CVE Low expat-2.2.5-10.el8

VAT: https://vat.dso.mil/vat/image?imageName=frontiertechnology/cortex/dbmigration-init&tag=v1.2&branch=master
More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/frontiertechnology/cortex/dbmigration-init/-/jobs/14727201

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the ~"Hardening::Approval" label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications
  • Send approval request to Authorizing Official
  • Close issue after approval from Authorizing Official

Note: If the above approval process is rejected for any reason, the Approval label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Approval label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by Ghost User
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information