UNCLASSIFIED - NO CUI

Skip to content

chore(findings): pingam

Summary

pingam has 178 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=pingam&tag=v8.0.1&branch=master

EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.

id source severity package impact workaround epss_score kev
CVE-2012-5370 Anchore CVE Medium jruby-9.4.8.0 0.00604 false
CVE-2025-48924 Twistlock CVE Medium commons-lang_commons-lang-2.6 0.00309 false
CVE-2025-48924 Twistlock CVE Medium org.apache.commons_commons-lang3-3.17.0 0.00309 false
CVE-2025-53506 Twistlock CVE Medium tomcat-coyote-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-fr-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-util-scan-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-juli-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-ru-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-dbcp-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-zh-CN-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-es-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-de-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-cs-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-ko-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-util-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-jdbc-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-ja-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-jni-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-websocket-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-api-10.1.41 0.00182 false
CVE-2025-53506 Anchore CVE High tomcat-i18n-pt-BR-10.1.41 0.00182 false
CVE-2025-53506 Twistlock CVE Medium tomcat-util-10.1.41 0.00182 false
CVE-2025-48989 Twistlock CVE High tomcat-coyote-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-juli-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-de-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-dbcp-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-ko-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-cs-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-zh-CN-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-util-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-util-scan-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-ja-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-ru-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-websocket-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-es-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-jni-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-jdbc-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-pt-BR-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-i18n-fr-10.1.41 0.00177 false
CVE-2025-48989 Anchore CVE High tomcat-api-10.1.41 0.00177 false
CVE-2025-48989 Twistlock CVE High tomcat-util-10.1.41 0.00177 false
CVE-2025-50106 Anchore CVE High openjdk-17.0.15+6-LTS 0.00174 false
CVE-2025-50106 Twistlock CVE High java-17.0.15 0.00174 false
CVE-2025-30749 Anchore CVE High openjdk-17.0.15+6-LTS 0.00174 false
CVE-2025-30749 Twistlock CVE High java-17.0.15 0.00174 false
CVE-2025-52520 Anchore CVE High tomcat-util-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-websocket-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-zh-CN-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-jni-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-ru-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-api-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-juli-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-jdbc-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-dbcp-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-cs-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-ko-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-ja-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-de-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-fr-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-es-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-i18n-pt-BR-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-util-scan-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High catalina-10.1.41 0.00153 false
CVE-2025-52520 Anchore CVE High tomcat-coyote-10.1.41 0.00153 false
CVE-2025-52520 Twistlock CVE Low tomcat-util-10.1.41 0.00153 false
CVE-2024-43126 Anchore CVE High opentelemetry-exporter-sender-jdk-1.45.0 0.00141 false
CVE-2025-46392 Twistlock CVE Low commons-configuration_commons-configuration-1.10 0.00117 false
CVE-2025-48976 Twistlock CVE Low commons-fileupload_commons-fileupload-1.5 0.00057 false
CVE-2025-48976 Twistlock CVE Medium commons-fileupload_commons-fileupload-1.5-forgerock-jakarta-2 0.00057 false
CVE-2025-48734 Twistlock CVE Low commons-beanutils_commons-beanutils-1.9.4 0.00056 false
CVE-2025-8916 Twistlock CVE Medium org.bouncycastle_bcpkix-fips-2.0.7 0.00055 false
CVE-2025-8885 Twistlock CVE Medium org.bouncycastle_bc-fips-2.0.0 0.00055 false
CVE-2025-49125 Twistlock CVE Low tomcat-util-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-ru-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-es-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-jdbc-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-dbcp-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-websocket-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High catalina-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-cs-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-juli-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-coyote-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-ja-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-zh-CN-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-api-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-fr-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-util-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-util-scan-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-de-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-ko-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-i18n-pt-BR-10.1.41 0.00055 false
CVE-2025-49125 Anchore CVE High tomcat-jni-10.1.41 0.00055 false
CVE-2025-50059 Anchore CVE High openjdk-17.0.15+6-LTS 0.00054 false
CVE-2025-50059 Twistlock CVE High java-17.0.15 0.00054 false
CVE-2025-48988 Twistlock CVE Medium tomcat-util-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-ko-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-de-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-util-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-pt-BR-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-jni-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-util-scan-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-jdbc-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-juli-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-es-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High catalina-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-fr-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-dbcp-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-coyote-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-cs-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-ja-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-zh-CN-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-i18n-ru-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-api-10.1.41 0.00052 false
CVE-2025-48988 Anchore CVE High tomcat-websocket-10.1.41 0.00052 false
CVE-2024-39657 Anchore CVE High opentelemetry-exporter-sender-jdk-1.45.0 0.00048 false
CVE-2025-27820 Twistlock CVE High org.apache.httpcomponents.client5_httpclient5-5.4.1 0.00043 false
CVE-2025-30754 Anchore CVE Medium openjdk-17.0.15+6-LTS 0.00036 false
CVE-2025-30754 Twistlock CVE Medium java-17.0.15 0.00036 false
CVE-2025-46551 Twistlock CVE Medium rubygems_jruby-openssl-0.15.3 0.00034 false
CVE-2025-46551 Twistlock CVE Medium org.jruby_jruby-9.4.8.0 0.00034 false
CVE-2025-49124 Twistlock CVE Low tomcat-util-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-zh-CN-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-websocket-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-dbcp-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High catalina-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-cs-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-de-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-util-scan-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-pt-BR-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-util-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-es-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-coyote-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-jdbc-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-api-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-jni-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-ru-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-juli-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-ja-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-ko-10.1.41 0.00016 false
CVE-2025-49124 Anchore CVE High tomcat-i18n-fr-10.1.41 0.00016 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-zh-CN-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-dbcp-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-ja-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-ko-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-jdbc-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-fr-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-pt-BR-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-cs-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-juli-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-es-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-util-scan-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-ru-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-jni-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-i18n-de-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-util-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-api-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-websocket-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium catalina-10.1.41 0.00012 false
CVE-2025-55668 Anchore CVE Medium tomcat-coyote-10.1.41 0.00012 false
CVE-2025-55668 Twistlock CVE Medium tomcat-util-10.1.41 0.00012 false
GHSA-wxr5-93ph-8wr9 Anchore CVE High commons-beanutils-1.9.4 N/A N/A
GHSA-wxr5-93ph-8wr9 Anchore CVE High commons-beanutils-1.9.4 N/A N/A
GHSA-vv7r-c36w-3prj Anchore CVE High commons-fileupload-1.5-forgerock-jakarta-2 N/A N/A
GHSA-pvp8-3xj6-8c6x Anchore CVE Low commons-configuration-1.10 N/A N/A
GHSA-pvp8-3xj6-8c6x Anchore CVE Low commons-configuration-1.10 N/A N/A
GHSA-j288-q9x7-2f5v Anchore CVE Medium commons-lang-2.6 N/A N/A
GHSA-j288-q9x7-2f5v Anchore CVE Medium commons-lang3-3.17.0 N/A N/A
GHSA-j288-q9x7-2f5v Anchore CVE Medium commons-lang-2.6 N/A N/A
GHSA-gqp3-2cvr-x8m3 Anchore CVE High tomcat-coyote-10.1.41 N/A N/A
GHSA-73m2-qfq3-56cx Anchore CVE High httpclient5-5.4.1 N/A N/A
GHSA-73m2-qfq3-56cx Anchore CVE High httpclient5-5.4.1 N/A N/A
GHSA-72qj-48g4-5xgx Anchore CVE Medium jruby-9.4.8.0 N/A N/A
GHSA-72qj-48g4-5xgx Anchore CVE Medium jruby-openssl-0.15.3 N/A N/A
GHSA-67mf-3cr5-8w23 Anchore CVE Medium bc-fips-2.0.0 N/A N/A
GHSA-67mf-3cr5-8w23 Anchore CVE Medium bc-fips-2.0.0 N/A N/A
GHSA-4cx2-fc23-5wg6 Anchore CVE Medium bcpkix-fips-2.0.7 N/A N/A
GHSA-4cx2-fc23-5wg6 Anchore CVE Medium bcpkix-fips-2.0.7 N/A N/A
GHSA-25xr-qj8w-c4vf Anchore CVE Medium tomcat-coyote-10.1.41 N/A N/A

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=pingam&tag=v8.0.1&branch=master

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Verification label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by CHORE_TOKEN
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information