UNCLASSIFIED - NO CUI

Skip to content

chore(findings): jetstack/cert-manager/cert-manager-controller-011

Summary

jetstack/cert-manager/cert-manager-controller-011 has 87 new findings discovered during continuous monitoring.

id source severity package
CCE-88964-2 OSCAP Compliance Medium
CCE-83634-6 OSCAP Compliance Medium
CVE-2023-39323 Twistlock CVE Critical go-1.13.1
CVE-2023-29405 Twistlock CVE Critical go-1.13.1
CVE-2023-29404 Twistlock CVE Critical go-1.13.1
CVE-2023-29402 Twistlock CVE Critical go-1.13.1
CVE-2023-24540 Twistlock CVE Critical go-1.13.1
CVE-2023-24538 Twistlock CVE Critical go-1.13.1
CVE-2021-38297 Twistlock CVE Critical go-1.13.1
CVE-2022-23806 Twistlock CVE Critical go-1.13.1
CVE-2023-29403 Twistlock CVE High go-1.13.1
CVE-2022-30580 Twistlock CVE High go-1.13.1
CVE-2023-24537 Twistlock CVE High go-1.13.1
CVE-2023-24536 Twistlock CVE High go-1.13.1
CVE-2023-24534 Twistlock CVE High go-1.13.1
CVE-2022-41725 Twistlock CVE High go-1.13.1
CVE-2022-41724 Twistlock CVE High go-1.13.1
CVE-2022-41723 Twistlock CVE High go-1.13.1
CVE-2022-41716 Twistlock CVE High go-1.13.1
CVE-2022-41715 Twistlock CVE High go-1.13.1
CVE-2022-32189 Twistlock CVE High go-1.13.1
CVE-2022-30635 Twistlock CVE High go-1.13.1
CVE-2022-30633 Twistlock CVE High go-1.13.1
CVE-2022-30632 Twistlock CVE High go-1.13.1
CVE-2022-30631 Twistlock CVE High go-1.13.1
CVE-2022-30630 Twistlock CVE High go-1.13.1
CVE-2022-2880 Twistlock CVE High go-1.13.1
CVE-2022-2879 Twistlock CVE High go-1.13.1
CVE-2022-28327 Twistlock CVE High go-1.13.1
CVE-2022-28131 Twistlock CVE High go-1.13.1
CVE-2022-27664 Twistlock CVE High go-1.13.1
CVE-2022-24921 Twistlock CVE High go-1.13.1
CVE-2022-24675 Twistlock CVE High go-1.13.1
CVE-2022-23773 Twistlock CVE High go-1.13.1
CVE-2022-23772 Twistlock CVE High go-1.13.1
CVE-2021-44716 Twistlock CVE High go-1.13.1
CVE-2021-41772 Twistlock CVE High go-1.13.1
CVE-2021-41771 Twistlock CVE High go-1.13.1
CVE-2021-39293 Twistlock CVE High go-1.13.1
CVE-2021-33198 Twistlock CVE High go-1.13.1
CVE-2021-33196 Twistlock CVE High go-1.13.1
CVE-2021-33194 Twistlock CVE High go-1.13.1
CVE-2021-29923 Twistlock CVE High go-1.13.1
CVE-2021-27918 Twistlock CVE High go-1.13.1
CVE-2020-7919 Twistlock CVE High go-1.13.1
CVE-2020-28367 Twistlock CVE High go-1.13.1
CVE-2020-28366 Twistlock CVE High go-1.13.1
CVE-2020-28362 Twistlock CVE High go-1.13.1
CVE-2020-16845 Twistlock CVE High go-1.13.1
CVE-2019-17596 Twistlock CVE High go-1.13.1
CVE-2023-29400 Twistlock CVE High go-1.13.1
CVE-2023-24539 Twistlock CVE High go-1.13.1
CVE-2021-33195 Twistlock CVE High go-1.13.1
CVE-2023-29406 Twistlock CVE Medium go-1.13.1
CVE-2022-32148 Twistlock CVE Medium go-1.13.1
CVE-2022-1705 Twistlock CVE Medium go-1.13.1
CVE-2021-34558 Twistlock CVE Medium go-1.13.1
CVE-2021-3114 Twistlock CVE Medium go-1.13.1
CVE-2023-39319 Twistlock CVE Medium go-1.13.1
CVE-2023-39318 Twistlock CVE Medium go-1.13.1
CVE-2020-24553 Twistlock CVE Medium go-1.13.1
CVE-2021-36221 Twistlock CVE Medium go-1.13.1
CVE-2021-31525 Twistlock CVE Medium go-1.13.1
CVE-2020-15586 Twistlock CVE Medium go-1.13.1
CVE-2020-29511 Twistlock CVE Medium go-1.13.1
CVE-2020-29510 Twistlock CVE Medium go-1.13.1
CVE-2020-29509 Twistlock CVE Medium go-1.13.1
CVE-2022-1962 Twistlock CVE Medium go-1.13.1
CVE-2023-29409 Twistlock CVE Medium go-1.13.1
CVE-2023-24532 Twistlock CVE Medium go-1.13.1
CVE-2022-41717 Twistlock CVE Medium go-1.13.1
CVE-2021-33197 Twistlock CVE Medium go-1.13.1
CVE-2022-30629 Twistlock CVE Low go-1.13.1
CVE-2023-45287 Twistlock CVE High go-1.13.1
CVE-2023-45285 Twistlock CVE High go-1.13.1
CVE-2023-39326 Twistlock CVE Medium go-1.13.1
CVE-2020-0601 Twistlock CVE High go-1.13.1
CVE-2023-46324 Twistlock CVE High go-1.13.1
CVE-2023-45283 Twistlock CVE High go-1.13.1
CVE-2022-41722 Twistlock CVE High go-1.13.1
CVE-2022-41720 Twistlock CVE High go-1.13.1
CVE-2022-30634 Twistlock CVE High go-1.13.1
CVE-2022-29804 Twistlock CVE High go-1.13.1
CVE-2021-3115 Twistlock CVE High go-1.13.1
CVE-2023-45284 Twistlock CVE Medium go-1.13.1
CVE-2022-29526 Twistlock CVE Medium go-1.13.1
CVE-2021-44717 Twistlock CVE Medium go-1.13.1

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=jetstack/cert-manager/cert-manager-controller-011&tag=v0.11.0&branch=master

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Verification label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information