UNCLASSIFIED - NO CUI

Skip to content

chore(findings): opensource/r/shiny

Summary

opensource/r/shiny has 31 new findings discovered during continuous monitoring.

id source severity package
CCE-85888-6 OSCAP Compliance Medium
CVE-2022-24999 Twistlock CVE High qs-6.9.6
CVE-2022-24999 Twistlock CVE High express-4.17.2
CVE-2022-43680 Twistlock CVE Medium expat-devel-2.2.5-10.el8
CVE-2022-43548 Twistlock CVE Medium nodejs-16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-43548 Twistlock CVE Medium npm-8.15.0-1.16.17.1.1.module+el8.6.0+16848+a483195a
CVE-2022-43548 Twistlock CVE Medium nodejs-full-i18n-16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-24999 Twistlock CVE Medium nodejs-full-i18n-16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-24999 Twistlock CVE Medium nodejs-16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-24999 Twistlock CVE Medium npm-8.15.0-1.16.17.1.1.module+el8.6.0+16848+a483195a
CVE-2022-3857 Twistlock CVE Low libpng-devel-1.6.34-5.el8
CVE-2019-7317 Twistlock CVE Low libpng-devel-1.6.34-5.el8
CVE-2022-43680 Anchore CVE Medium expat-devel-2.2.5-10.el8
CVE-2022-35255 Anchore CVE High nodejs-full-i18n-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-35256 Anchore CVE Medium nodejs-docs-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-35255 Anchore CVE High nodejs-docs-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-35256 Anchore CVE Medium nodejs-full-i18n-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-35256 Anchore CVE Medium nodejs-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-3857 Anchore CVE Low libpng-devel-2:1.6.34-5.el8
CVE-2022-35255 Anchore CVE High npm-1:8.15.0-1.16.17.1.1.module+el8.6.0+16848+a483195a
CVE-2022-35256 Anchore CVE Medium npm-1:8.15.0-1.16.17.1.1.module+el8.6.0+16848+a483195a
CVE-2022-35255 Anchore CVE High nodejs-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-43548 Anchore CVE Medium nodejs-full-i18n-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-3517 Anchore CVE Medium nodejs-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-3517 Anchore CVE Medium nodejs-full-i18n-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-3517 Anchore CVE Medium npm-1:8.15.0-1.16.17.1.1.module+el8.6.0+16848+a483195a
CVE-2022-43548 Anchore CVE Medium nodejs-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-3517 Anchore CVE Medium nodejs-docs-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2022-43548 Anchore CVE Medium npm-1:8.15.0-1.16.17.1.1.module+el8.6.0+16848+a483195a
CVE-2022-43548 Anchore CVE Medium nodejs-docs-1:16.17.1-1.module+el8.6.0+16848+a483195a
CVE-2018-16428 Twistlock CVE Low glib2-2.56.4-158.el8_6.1

VAT: https://vat.dso.mil/vat/image?imageName=opensource/r/shiny&tag=1.5.19.995&branch=master
More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/opensource/r/shiny/-/jobs/14697895

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the ~"Hardening::Approval" label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications
  • Send approval request to Authorizing Official
  • Close issue after approval from Authorizing Official

Note: If the above approval process is rejected for any reason, the Approval label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Approval label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by Ghost User
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information