UNCLASSIFIED - NO CUI

chore(findings): mitekanalytics/matlab-runtime

Summary

mitekanalytics/matlab-runtime has 204 new findings discovered during continuous monitoring.

id source severity package
CVE-2021-31535 Anchore CVE High libX11-1.7.0-9.el9
CVE-2022-1056 Anchore CVE Low libtiff-4.4.0-12.el9
CVE-2021-3782 Anchore CVE Medium libwayland-egl-1.21.0-1.el9
CVE-2021-37615 Anchore CVE Low exiv2-libs-0.27.5-2.el9
CVE-2022-33068 Anchore CVE Medium java-11-openjdk-devel-1:11.0.23.0.9-3.el9
CVE-2020-13956 Anchore CVE Medium commons-httpclient-3.1
CVE-2023-25434 Anchore CVE Medium libtiff-4.4.0-12.el9
CVE-2024-23252 Anchore CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
GHSA-3f7h-mf4q-vrm4 Anchore CVE Medium woodstox-core-6.2.8
CVE-2021-37621 Anchore CVE Low exiv2-libs-0.27.5-2.el9
CVE-2012-5783 Anchore CVE Medium commons-httpclient-3.1
CVE-2022-37050 Anchore CVE Medium poppler-glib-21.01.0-19.el9
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.15.3
CVE-2022-3555 Anchore CVE Low libX11-common-1.7.0-9.el9
CVE-2024-23284 Anchore CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2021-37616 Anchore CVE Low exiv2-libs-0.27.5-2.el9
CVE-2022-3554 Anchore CVE Medium libX11-xcb-1.7.0-9.el9
CVE-2022-37051 Anchore CVE Medium poppler-glib-21.01.0-19.el9
CVE-2023-4504 Anchore CVE Medium cups-libs-1:2.3.3op2-24.el9
CVE-2021-37620 Anchore CVE Low exiv2-0.27.5-2.el9
CVE-2017-17973 Anchore CVE Medium libtiff-4.4.0-12.el9
CVE-2024-23280 Anchore CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2017-16232 Anchore CVE Low libtiff-4.4.0-12.el9
CVE-2021-32815 Anchore CVE Low exiv2-0.27.5-2.el9
CVE-2022-3555 Anchore CVE Low libX11-xcb-1.7.0-9.el9
CVE-2018-13419 Anchore CVE Low libsndfile-1.0.31-8.el9
CVE-2021-3782 Anchore CVE Medium libwayland-server-1.21.0-1.el9
CVE-2023-39742 Anchore CVE Low giflib-5.2.1-9.el9
CVE-2021-37615 Anchore CVE Low exiv2-0.27.5-2.el9
CVE-2023-48161 Anchore CVE Medium java-11-openjdk-headless-1:11.0.23.0.9-3.el9
CVE-2021-37616 Anchore CVE Low exiv2-0.27.5-2.el9
CVE-2021-34334 Anchore CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-37620 Anchore CVE Low exiv2-libs-0.27.5-2.el9
CVE-2022-3554 Anchore CVE Medium libX11-common-1.7.0-9.el9
CVE-2022-37050 Anchore CVE Medium poppler-21.01.0-19.el9
CVE-2023-2004 Anchore CVE Low java-11-openjdk-headless-1:11.0.23.0.9-3.el9
CVE-2021-34335 Anchore CVE Low exiv2-0.27.5-2.el9
CVE-2023-6277 Anchore CVE Medium libtiff-4.4.0-12.el9
CVE-2020-18771 Anchore CVE Low exiv2-libs-0.27.5-2.el9
CVE-2022-27943 Anchore CVE Low libatomic-11.4.1-3.el9
CVE-2023-52356 Anchore CVE Medium libtiff-4.4.0-12.el9
CVE-2022-37052 Anchore CVE Medium poppler-glib-21.01.0-19.el9
CVE-2024-0985 Anchore CVE High postgresql-15.5
CVE-2017-6519 Anchore CVE Low avahi-libs-0.8-20.el9
CVE-2023-2004 Anchore CVE Low freetype-2.10.4-9.el9
CVE-2021-31535 Anchore CVE High libX11-common-1.7.0-9.el9
CVE-2024-23263 Anchore CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2022-30294 Anchore CVE Low webkit2gtk3-jsc-2.42.5-1.el9
CVE-2023-2004 Anchore CVE Low java-11-openjdk-devel-1:11.0.23.0.9-3.el9
CVE-2022-3554 Anchore CVE Medium libX11-1.7.0-9.el9
CVE-2024-23226 Anchore CVE High webkit2gtk3-jsc-2.42.5-1.el9
CVE-2023-2004 Anchore CVE Low java-11-openjdk-1:11.0.23.0.9-3.el9
CVE-2022-37051 Anchore CVE Medium poppler-21.01.0-19.el9
CVE-2023-25435 Anchore CVE Medium libtiff-4.4.0-12.el9
CVE-2021-34335 Anchore CVE Low exiv2-libs-0.27.5-2.el9
CVE-2023-42843 Anchore CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2022-3857 Anchore CVE Low java-11-openjdk-1:11.0.23.0.9-3.el9
CVE-2021-3782 Anchore CVE Medium libwayland-client-1.21.0-1.el9
CVE-2021-37621 Anchore CVE Low exiv2-0.27.5-2.el9
CVE-2024-23254 Anchore CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2023-48161 Anchore CVE Medium java-11-openjdk-devel-1:11.0.23.0.9-3.el9
CVE-2022-33068 Anchore CVE Medium java-11-openjdk-headless-1:11.0.23.0.9-3.el9
CVE-2021-25317 Anchore CVE Low cups-libs-1:2.3.3op2-24.el9
CVE-2023-1916 Anchore CVE Low libtiff-4.4.0-12.el9
GHSA-4265-ccf5-phj5 Anchore CVE High commons-compress-1.21
CVE-2020-23922 Anchore CVE Low giflib-5.2.1-9.el9
CVE-2021-34334 Anchore CVE Low exiv2-0.27.5-2.el9
CVE-2022-3857 Anchore CVE Low java-11-openjdk-devel-1:11.0.23.0.9-3.el9
CVE-2022-33068 Anchore CVE Medium java-11-openjdk-1:11.0.23.0.9-3.el9
CVE-2023-48161 Anchore CVE Medium java-11-openjdk-1:11.0.23.0.9-3.el9
CVE-2022-48622 Anchore CVE Medium gdk-pixbuf2-modules-2.42.6-3.el9
CVE-2023-42950 Anchore CVE High webkit2gtk3-jsc-2.42.5-1.el9
CVE-2022-37052 Anchore CVE Medium poppler-21.01.0-19.el9
CVE-2023-48161 Anchore CVE Medium giflib-5.2.1-9.el9
CVE-2022-3857 Anchore CVE Low java-11-openjdk-headless-1:11.0.23.0.9-3.el9
CVE-2021-3997 Anchore CVE Medium systemd-udev-252-32.el9_4
CVE-2022-0529 Anchore CVE Low unzip-6.0-56.el9
CVE-2022-3555 Anchore CVE Low libX11-1.7.0-9.el9
CVE-2022-3857 Anchore CVE Low libpng-2:1.6.37-12.el9
CVE-2023-52355 Anchore CVE Medium libtiff-4.4.0-12.el9
CVE-2021-3782 Anchore CVE Medium libwayland-cursor-1.21.0-1.el9
GHSA-4g9r-vxhx-9pgx Anchore CVE High commons-compress-1.21
CVE-2023-42956 Anchore CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2023-25433 Anchore CVE Medium libtiff-4.4.0-12.el9
CVE-2021-32815 Anchore CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-31535 Anchore CVE High libX11-xcb-1.7.0-9.el9
CVE-2022-0530 Anchore CVE Low unzip-6.0-56.el9
CVE-2022-48622 Anchore CVE Medium gdk-pixbuf2-2.42.6-3.el9
CVE-2020-18771 Anchore CVE Low exiv2-0.27.5-2.el9
CVE-2024-23226 Twistlock CVE Critical webkit2gtk3-jsc-2.42.5-1.el9
CVE-2023-42950 Twistlock CVE Critical webkit2gtk3-jsc-2.42.5-1.el9
CVE-2020-11988 Twistlock CVE High xmlgraphics-commons-svn-trunk
CVE-2021-31535 Twistlock CVE Medium libX11-xcb-1.7.0-9.el9
CVE-2021-31535 Twistlock CVE Medium libX11-common-1.7.0-9.el9
CVE-2021-31535 Twistlock CVE Medium libX11-1.7.0-9.el9
CVE-2023-52356 Twistlock CVE Medium libtiff-4.4.0-12.el9
CVE-2023-52355 Twistlock CVE Medium libtiff-4.4.0-12.el9
CVE-2022-48622 Twistlock CVE Medium gdk-pixbuf2-2.42.6-3.el9
CVE-2022-48622 Twistlock CVE Medium gdk-pixbuf2-modules-2.42.6-3.el9
CVE-2023-48161 Twistlock CVE Medium java-11-openjdk-devel-11.0.23.0.9-3.el9
CVE-2023-48161 Twistlock CVE Medium java-11-openjdk-headless-11.0.23.0.9-3.el9
CVE-2023-48161 Twistlock CVE Medium giflib-5.2.1-9.el9
CVE-2023-48161 Twistlock CVE Medium java-11-openjdk-11.0.23.0.9-3.el9
CVE-2023-4504 Twistlock CVE Medium cups-libs-2.3.3op2-24.el9
CVE-2021-3782 Twistlock CVE Medium libwayland-cursor-1.21.0-1.el9
CVE-2021-3782 Twistlock CVE Medium libwayland-client-1.21.0-1.el9
CVE-2021-3782 Twistlock CVE Medium libwayland-egl-1.21.0-1.el9
CVE-2021-3782 Twistlock CVE Medium libwayland-server-1.21.0-1.el9
CVE-2024-23284 Twistlock CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2024-23280 Twistlock CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2024-23263 Twistlock CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2024-23254 Twistlock CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2023-6277 Twistlock CVE Medium libtiff-4.4.0-12.el9
CVE-2023-42956 Twistlock CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2022-40152 Twistlock CVE Medium com.fasterxml.woodstox_woodstox-core-6.2.8
CVE-2022-37051 Twistlock CVE Medium poppler-21.01.0-19.el9
CVE-2022-37051 Twistlock CVE Medium poppler-glib-21.01.0-19.el9
CVE-2022-37050 Twistlock CVE Medium poppler-21.01.0-19.el9
CVE-2022-37050 Twistlock CVE Medium poppler-glib-21.01.0-19.el9
CVE-2023-3164 Twistlock CVE Medium libtiff-4.4.0-12.el9
CVE-2023-25435 Twistlock CVE Medium libtiff-4.4.0-12.el9
CVE-2023-25434 Twistlock CVE Medium libtiff-4.4.0-12.el9
CVE-2023-25433 Twistlock CVE Medium libtiff-4.4.0-12.el9
CVE-2022-33068 Twistlock CVE Medium java-11-openjdk-devel-11.0.23.0.9-3.el9
CVE-2022-33068 Twistlock CVE Medium java-11-openjdk-11.0.23.0.9-3.el9
CVE-2022-33068 Twistlock CVE Medium java-11-openjdk-headless-11.0.23.0.9-3.el9
CVE-2021-3997 Twistlock CVE Medium systemd-udev-252-32.el9_4
CVE-2023-42843 Twistlock CVE Medium webkit2gtk3-jsc-2.42.5-1.el9
CVE-2020-18771 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2020-18771 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2023-1916 Twistlock CVE Low libtiff-4.4.0-12.el9
CVE-2017-6519 Twistlock CVE Low avahi-libs-0.8-20.el9
CVE-2022-3857 Twistlock CVE Low java-11-openjdk-devel-11.0.23.0.9-3.el9
CVE-2022-3857 Twistlock CVE Low libpng-1.6.37-12.el9
CVE-2022-3857 Twistlock CVE Low java-11-openjdk-headless-11.0.23.0.9-3.el9
CVE-2022-3857 Twistlock CVE Low java-11-openjdk-11.0.23.0.9-3.el9
CVE-2022-27943 Twistlock CVE Low libatomic-11.4.1-3.el9
CVE-2022-1056 Twistlock CVE Low libtiff-4.4.0-12.el9
CVE-2021-37623 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-37623 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2021-37622 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-37622 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2021-37621 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2021-37621 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-37616 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2021-37616 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-34334 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-34334 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2021-32815 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-32815 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2020-23922 Twistlock CVE Low giflib-5.2.1-9.el9
CVE-2021-37620 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-37620 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2021-37615 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2021-37615 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2021-34335 Twistlock CVE Low exiv2-0.27.5-2.el9
CVE-2021-34335 Twistlock CVE Low exiv2-libs-0.27.5-2.el9
CVE-2020-9488 Twistlock CVE Low org.apache.logging.log4j_log4j-1.2-api-2
CVE-2023-39742 Twistlock CVE Low giflib-5.2.1-9.el9
CVE-2021-25317 Twistlock CVE Low cups-libs-2.3.3op2-24.el9
CVE-2019-2699 Twistlock CVE Critical java-1.8.0_202
CVE-2020-2805 Twistlock CVE High java-1.8.0_202
CVE-2020-2803 Twistlock CVE High java-1.8.0_202
CVE-2020-2604 Twistlock CVE High java-1.8.0_202
CVE-2019-2698 Twistlock CVE High java-1.8.0_202
CVE-2019-2697 Twistlock CVE High java-1.8.0_202
CVE-2024-0985 Twistlock CVE High postgres-15.5
CVE-2022-34169 Twistlock CVE High java-1.8.0_202
CVE-2019-2602 Twistlock CVE High java-1.8.0_202
CVE-2023-21930 Twistlock CVE High java-1.8.0_202
CVE-2023-21967 Twistlock CVE Medium java-1.8.0_202
CVE-2023-21954 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21541 Twistlock CVE Medium java-1.8.0_202
CVE-2021-2161 Twistlock CVE Medium java-1.8.0_202
CVE-2019-2684 Twistlock CVE Medium java-1.8.0_202
CVE-2024-26308 Twistlock CVE Medium org.apache.commons_commons-compress-1.21
CVE-2024-25710 Twistlock CVE Medium org.apache.commons_commons-compress-1.21
CVE-2023-21939 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21540 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21365 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21360 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21349 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21341 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21340 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21305 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21299 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21296 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21294 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21293 Twistlock CVE Medium java-1.8.0_202
CVE-2022-21282 Twistlock CVE Medium java-1.8.0_202
CVE-2021-2163 Twistlock CVE Medium java-1.8.0_202
CVE-2020-2830 Twistlock CVE Medium java-1.8.0_202
CVE-2020-2781 Twistlock CVE Medium java-1.8.0_202
CVE-2020-2800 Twistlock CVE Medium java-1.8.0_202
CVE-2023-21938 Twistlock CVE Low java-1.8.0_202
CVE-2023-21937 Twistlock CVE Low java-1.8.0_202
CVE-2022-21248 Twistlock CVE Low java-1.8.0_202
CVE-2020-2773 Twistlock CVE Low java-1.8.0_202
CVE-2020-2757 Twistlock CVE Low java-1.8.0_202
CVE-2020-2756 Twistlock CVE Low java-1.8.0_202
CVE-2020-2659 Twistlock CVE Low java-1.8.0_202
CVE-2023-45145 Twistlock CVE Low redis-server-6.2.13
CVE-2020-36023 Twistlock CVE Medium poppler-21.01.0-19.el9
CVE-2020-36023 Twistlock CVE Medium poppler-glib-21.01.0-19.el9

VAT: https://vat.dso.mil/vat/image?imageName=mitekanalytics/matlab-runtime&tag=v0.11.0-2024-05-06-sha-5404cef&branch=master
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=mitekanalytics/matlab-runtime&tag=v0.7.0-2024-02-24-sha-2bdec0e&branch=master

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Verification label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by Al Fontaine
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information