chore(findings): google/golang/debian/golang-1.20
Summary
google/golang/debian/golang-1.20 has 29 new findings discovered during continuous monitoring.
id | source | severity | package |
---|---|---|---|
xccdf_org.ssgproject.content_rule_package_ntp_installed | OSCAP Compliance | High | |
xccdf_org.ssgproject.content_rule_package_rsyslog_installed | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_package_syslogng_installed | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_partition_for_home | OSCAP Compliance | Low | |
xccdf_org.ssgproject.content_rule_partition_for_tmp | OSCAP Compliance | Low | |
xccdf_org.ssgproject.content_rule_partition_for_var | OSCAP Compliance | Low | |
xccdf_org.ssgproject.content_rule_partition_for_var_log | OSCAP Compliance | Low | |
xccdf_org.ssgproject.content_rule_partition_for_var_log_audit | OSCAP Compliance | Low | |
xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_rsyslog_files_ownership | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_rsyslog_files_permissions | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_service_rsyslog_enabled | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_service_syslogng_enabled | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable | OSCAP Compliance | Medium | |
xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space | OSCAP Compliance | Medium | |
CVE-2023-50387 | Twistlock CVE | High | systemd-247.3-7+deb11u4 |
CVE-2024-0553 | Twistlock CVE | Low | gnutls28-3.7.1-5+deb11u4 |
CVE-2018-5709 | Twistlock CVE | Low | krb5-1.18.3-6+deb11u4 |
CVE-2024-0727 | Twistlock CVE | Low | openssl-1.1.1w-0+deb11u1 |
CVE-2024-26462 | Twistlock CVE | Low | krb5-1.18.3-6+deb11u4 |
CVE-2024-26461 | Twistlock CVE | Low | krb5-1.18.3-6+deb11u4 |
CVE-2024-26458 | Twistlock CVE | Low | krb5-1.18.3-6+deb11u4 |
CVE-2023-50868 | Twistlock CVE | Low | systemd-247.3-7+deb11u4 |
CVE-2010-0928 | Twistlock CVE | Low | openssl-1.1.1w-0+deb11u1 |
CVE-2007-6755 | Twistlock CVE | Low | openssl-1.1.1w-0+deb11u1 |
CVE-2024-2236 | Twistlock CVE | Low | libgcrypt20-1.8.7-6 |
CVE-2024-28757 | Twistlock CVE | Low | expat-2.2.10-2+deb11u5 |
VAT: https://vat.dso.mil/vat/image?imageName=google/golang/debian/golang-1.20&tag=1.20.12-debian&branch=master
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=google/golang/debian/golang-1.20&tag=1.20.12-debian&branch=master
Tasks
Contributor:
-
Provide justifications for findings in the VAT (docs) -
Apply the StatusVerification label to this issue and wait for feedback
Iron Bank:
-
Review findings and justifications
Note: If the above process is rejected for any reason, the
Verification
label will be removed and the issue will be sent back toOpen
. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add theVerification
label.
Questions?
Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding
.
Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.