chore(findings): mitre/saf/heimdall_tools
Summary
mitre/saf/heimdall_tools has 19 new findings discovered during continuous monitoring.
id | source | severity | package |
---|---|---|---|
CVE-2021-41098 | Twistlock CVE | High | nokogiri-1.11.7 |
GHSA-2rr5-8q37-2w7h | Anchore CVE | High | nokogiri-1.11.7 |
CVE-2021-30560 | Twistlock CVE | High | nokogiri-1.11.7 |
GHSA-fq42-c5rg-92c2 | Anchore CVE | High | nokogiri-1.11.7 |
GHSA-xxx9-3xcr-gjj3 | Anchore CVE | Medium | nokogiri-1.11.7 |
GHSA-crjr-9rc5-ghw8 | Anchore CVE | High | nokogiri-1.11.7 |
GHSA-gx8x-g87m-h5q6 | Anchore CVE | High | nokogiri-1.11.7 |
GHSA-v6gp-9mmm-c6p5 | Anchore CVE | High | nokogiri-1.11.7 |
CVE-2018-25032 | Twistlock CVE | High | nokogiri-1.11.7 |
CVE-2022-23437 | Twistlock CVE | Medium | nokogiri-1.11.7 |
CVE-2022-24839 | Twistlock CVE | High | nokogiri-1.11.7 |
CVE-2022-24836 | Twistlock CVE | High | nokogiri-1.11.7 |
GHSA-cgx6-hpwq-fhv5 | Anchore CVE | High | nokogiri-1.11.7 |
CVE-2022-29181 | Twistlock CVE | High | nokogiri-1.11.7 |
GHSA-xh29-r2w5-wx8m | Anchore CVE | High | nokogiri-1.11.7 |
CVE-2022-32511 | Twistlock CVE | Critical | jmespath-1.4.0 |
GHSA-5c5f-7vfq-3732 | Anchore CVE | Critical | jmespath-1.4.0 |
GHSA-2qc6-mcvw-92cw | Anchore CVE | Medium | nokogiri-1.11.7 |
GHSA-5pq7-52mg-hr42 | Anchore CVE | Medium | httparty-0.18.1 |
VAT: https://vat.dso.mil/vat/image?imageName=mitre/saf/heimdall_tools&tag=1.3.48&branch=master
More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/mitre/saf/heimdall_tools/-/jobs/12416991
Tasks
Contributor:
-
Provide justifications for findings in the VAT (docs) -
Apply the ~"Approval" label to this issue and wait for feedback
Iron Bank:
-
Review findings and justifications -
Send approval request to Authorizing Official -
Close issue after approval from Authorizing Official
Note: If the above approval process is rejected for any reason, the
Approval
label will be removed and the issue will be sent back toOpen
. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add theApproval
label.
Questions?
Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding
.
Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.