UNCLASSIFIED - NO CUI

chore(findings): kubeflow/katib/suggestion-nasrl-57c6abf76193

Summary

kubeflow/katib/suggestion-nasrl-57c6abf76193 has 52 new findings discovered during continuous monitoring.

id source package
GHSA-278g-rq84-9hmg anchore_cve tensorflow-1.15.5
GHSA-27j5-4p9v-pp67 anchore_cve tensorflow-1.15.5
GHSA-27qf-jwm8-g7f3 anchore_cve tensorflow-1.15.5
GHSA-2r8p-fg3c-wcj4 anchore_cve tensorflow-1.15.5
GHSA-2wmv-37vq-52g5 anchore_cve tensorflow-1.15.5
GHSA-3hxh-8cp2-g4hg anchore_cve tensorflow-1.15.5
GHSA-4xfp-4pfp-89wg anchore_cve tensorflow-1.15.5
GHSA-5hj3-vjjf-f5m7 anchore_cve tensorflow-1.15.5
GHSA-5xwc-mrhx-5g3m anchore_cve tensorflow-1.15.5
GHSA-6gv8-p3vj-pxvr anchore_cve tensorflow-1.15.5
GHSA-6p5r-g9mq-ggh2 anchore_cve tensorflow-1.15.5
GHSA-7fvx-3jfc-2cpc anchore_cve tensorflow-1.15.5
GHSA-7ghq-fvr3-pj2x anchore_cve tensorflow-1.15.5
GHSA-95xm-g58g-3p88 anchore_cve tensorflow-1.15.5
GHSA-9697-98pf-4rw7 anchore_cve tensorflow-1.15.5
GHSA-9c8h-2mv3-49ww anchore_cve tensorflow-1.15.5
GHSA-9c8h-vvrj-w2p8 anchore_cve tensorflow-1.15.5
GHSA-9w2p-5mgw-p94c anchore_cve tensorflow-1.15.5
GHSA-c5x2-p679-95wc anchore_cve tensorflow-1.15.5
GHSA-c9qf-r67m-p7cg anchore_cve tensorflow-1.15.5
GHSA-cgfm-62j4-v4rf anchore_cve tensorflow-1.15.5
GHSA-ch4f-829c-v5pw anchore_cve tensorflow-1.15.5
GHSA-cm5x-837x-jf3c anchore_cve tensorflow-1.15.5
GHSA-cmgw-8vpc-rc59 anchore_cve tensorflow-1.15.5
GHSA-f5cx-5wr3-5qrc anchore_cve tensorflow-1.15.5
GHSA-f8h4-7rgh-q2gm anchore_cve tensorflow-1.15.5
GHSA-fcwc-p4fc-c5cc anchore_cve tensorflow-1.15.5
GHSA-g25h-jr74-qp5j anchore_cve tensorflow-1.15.5
GHSA-g8wg-cjwc-xhhp anchore_cve tensorflow-1.15.5
GHSA-gf88-j2mg-cc82 anchore_cve tensorflow-1.15.5
GHSA-gh6x-4whr-2qv4 anchore_cve tensorflow-1.15.5
GHSA-h6jh-7gv5-28vg anchore_cve tensorflow-1.15.5
GHSA-hp4c-x6r7-6555 anchore_cve tensorflow-1.15.5
GHSA-hpv4-7p9c-mvfr anchore_cve tensorflow-1.15.5
GHSA-hwr7-8gxx-fj5p anchore_cve tensorflow-1.15.5
GHSA-m7fm-4jfh-jrg6 anchore_cve tensorflow-1.15.5
GHSA-mhhc-q96p-mfm9 anchore_cve tensorflow-1.15.5
GHSA-q3g3-h9r4-prrc anchore_cve tensorflow-1.15.5
GHSA-q7f7-544h-67h9 anchore_cve tensorflow-1.15.5
GHSA-qfpc-5pjr-mh26 anchore_cve tensorflow-1.15.5
GHSA-qjj8-32p7-h289 anchore_cve tensorflow-1.15.5
GHSA-qr82-2c78-4m8h anchore_cve tensorflow-1.15.5
GHSA-r4c4-5fpq-56wg anchore_cve tensorflow-1.15.5
GHSA-r6jx-9g48-2r5r anchore_cve tensorflow-1.15.5
GHSA-v768-w7m9-2vmm anchore_cve tensorflow-1.15.5
GHSA-v82p-hv3v-p6qp anchore_cve tensorflow-1.15.5
GHSA-vmjw-c2vp-p33c anchore_cve tensorflow-1.15.5
GHSA-w4xf-2pqw-5mq7 anchore_cve tensorflow-1.15.5
GHSA-w74j-v8xh-3w5h anchore_cve tensorflow-1.15.5
GHSA-wp77-4gmm-7cq8 anchore_cve tensorflow-1.15.5
CVE-2020-15265 twistlock_cve tensorflow-1.15.5
CVE-2020-15266 twistlock_cve tensorflow-1.15.5

More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/kubeflow/katib/suggestion-nasrl-57c6abf76193/-/jobs/6072900

Definition of Done

Justifications:

  • All findings have been justified
  • Justifications have been provided to the container hardening team

Approval Process:

  • Findings Approver has reviewed and approved all justifications
  • Approval request has been sent to Authorizing Official
  • Approval request has been processed by Authorizing Official
Edited by Joshua Eason