UNCLASSIFIED - NO CUI

chore(findings): opensource/istio-1.7/pilot-1.7

Summary

opensource/istio-1.7/pilot-1.7 has 3 new findings discovered during continuous monitoring.

id source package
CVE-2021-42694 twistlock_cve libgcc-8.5.0-4.el8_5
CVE-2021-3974 twistlock_cve vim-minimal-8.0.1763-16.el8
CVE-2020-17049 twistlock_cve krb5-libs-1.18.2-14.el8

More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/opensource/istio-1.7/pilot-1.7/-/jobs/8185586

Definition of Done

Justifications:

  • All findings have been justified
  • Justifications have been provided to the container hardening team

Approval Process:

  • Findings Approver has reviewed and approved all justifications
  • Approval request has been sent to Authorizing Official
  • Approval request has been processed by Authorizing Official
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information