UNCLASSIFIED - NO CUI

chore(findings): security-compass/jitt/nginx

Summary

security-compass/jitt/nginx has 14 new findings discovered during continuous monitoring.

id source package
953dfbea1b1e9d5829fbed2e390bd3af anchore_comp None
CVE-2019-25013 anchore_cve glibc-langpack-en-2.28-127.el8_3.2
CVE-2020-27618 anchore_cve glibc-langpack-en-2.28-127.el8_3.2
CVE-2021-27645 anchore_cve glibc-langpack-en-2.28-127.el8_3.2
CVE-2021-3326 anchore_cve glibc-langpack-en-2.28-127.el8_3.2
CVE-2021-23840 anchore_cve openssl-1.1.1g-15.el8_3
CVE-2021-23841 anchore_cve openssl-1.1.1g-15.el8_3
CVE-2021-23239 anchore_cve sudo-1.8.29-6.el8_3.1
CVE-2021-23240 anchore_cve sudo-1.8.29-6.el8_3.1
CCE-83318-6 oscap_comp None
CVE-2021-23840 twistlock_cve openssl-1.1.1g-15.el8_3
See csv output stage for complete list of new findings.

Definition of Done

Justifications:

  • All findings have been justified
  • Justifications have been provided to the container hardening team
  • Approval label has been applied

Note: The justifications must be provided in a timely fashion. Failure to do so could result in new findings being identified which may start this process over.

Approval Process:

  • Findings Approver has reviewed and approved all justifications
  • Approval request has been sent to Authorizing Official
  • Approval request has been processed by Authorizing Official

Note: If the above approval process is kicked back for any reason, the Approval label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you may re-add the Approval label.