UNCLASSIFIED - NO CUI

chore(findings): ironbank-pipelines/rootless-podman

Summary

ironbank-pipelines/rootless-podman has 5 new findings discovered during continuous monitoring.

id source package
CVE-2021-20266 anchore_cve rpm-plugin-selinux-4.14.3-14.el8_4
CVE-2021-3421 anchore_cve rpm-plugin-selinux-4.14.3-14.el8_4
CVE-2021-35937 anchore_cve rpm-plugin-selinux-4.14.3-14.el8_4
CVE-2021-35938 anchore_cve rpm-plugin-selinux-4.14.3-14.el8_4
CVE-2021-35939 anchore_cve rpm-plugin-selinux-4.14.3-14.el8_4

More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/ironbank-pipelines/rootless-podman/-/jobs/4607173

Definition of Done

Justifications:

  • All findings have been justified
  • Justifications have been provided to the container hardening team

Approval Process:

  • Findings Approver has reviewed and approved all justifications
  • Approval request has been sent to Authorizing Official
  • Approval request has been processed by Authorizing Official