UNCLASSIFIED - NO CUI

chore(findings): grammatech/codesonar/codesonar-hub

Summary

grammatech/codesonar/codesonar-hub has 2 new findings discovered during continuous monitoring.

id source package
CVE-2021-20305 twistlock_cve gnutls-3.6.14-7.el8_3
CVE-2021-20305 twistlock_cve nettle-3.4.1-2.el8

More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/grammatech/codesonar/codesonar-hub/-/jobs/2616010

Definition of Done

Justifications:

  • All findings have been justified
  • Justifications have been provided to the container hardening team

Approval Process:

  • Findings Approver has reviewed and approved all justifications
  • Approval request has been sent to Authorizing Official
  • Approval request has been processed by Authorizing Official
Edited by Mark Hermeling