UNCLASSIFIED - NO CUI

Skip to content

chore(findings): beast-code/weapon-one/base-image

Summary

beast-code/weapon-one/base-image has 134 new findings discovered during continuous monitoring.

id source severity package
addbb93c22e9b0988b8b40392a4538cb Anchore Compliance Low
CVE-2023-29383 Anchore CVE Medium util-linux-2.32.1-42.el8_8
CVE-2021-35939 Anchore CVE Medium python3-rpm-4.14.3-26.el8
CVE-2021-35938 Anchore CVE Medium rpm-4.14.3-26.el8
CVE-2021-35938 Anchore CVE Medium rpm-build-libs-4.14.3-26.el8
CVE-2021-35938 Anchore CVE Medium python3-rpm-4.14.3-26.el8
CVE-2023-29469 Anchore CVE Medium libxml2-2.9.7-16.el8
CVE-2023-27536 Anchore CVE Medium curl-7.61.1-30.el8_8.2
CVE-2021-35937 Anchore CVE Medium rpm-build-libs-4.14.3-26.el8
CVE-2021-35938 Anchore CVE Medium rpm-libs-4.14.3-26.el8
CVE-2023-29383 Anchore CVE Medium libfdisk-2.32.1-42.el8_8
CVE-2023-28484 Anchore CVE Medium libxml2-2.9.7-16.el8
CVE-2021-35937 Anchore CVE Medium rpm-4.14.3-26.el8
CVE-2021-35937 Anchore CVE Medium python3-rpm-4.14.3-26.el8
CVE-2021-35939 Anchore CVE Medium rpm-4.14.3-26.el8
CVE-2023-29469 Anchore CVE Medium python3-libxml2-2.9.7-16.el8
CVE-2023-29383 Anchore CVE Medium libblkid-2.32.1-42.el8_8
CVE-2023-28484 Anchore CVE Medium python3-libxml2-2.9.7-16.el8
CVE-2023-29383 Anchore CVE Medium libuuid-2.32.1-42.el8_8
CVE-2023-29383 Anchore CVE Medium libmount-2.32.1-42.el8_8
CVE-2023-29383 Anchore CVE Medium libsmartcols-2.32.1-42.el8_8
CVE-2021-35939 Anchore CVE Medium rpm-libs-4.14.3-26.el8
CVE-2023-27536 Anchore CVE Medium libcurl-7.61.1-30.el8_8.2
CVE-2021-35939 Anchore CVE Medium rpm-build-libs-4.14.3-26.el8
CVE-2021-35937 Anchore CVE Medium rpm-libs-4.14.3-26.el8
CVE-2023-28321 Anchore CVE Medium curl-7.61.1-30.el8_8.2
CVE-2023-28321 Anchore CVE Medium libcurl-7.61.1-30.el8_8.2
CVE-2023-32681 Anchore CVE Medium python3-requests-2.20.0-2.1.el8_1
CVE-2023-2953 Anchore CVE Low openldap-2.4.46-18.el8
CVE-2023-2603 Anchore CVE Medium libcap-2.48-4.el8
CVE-2023-2602 Anchore CVE Low libcap-2.48-4.el8
CVE-2023-30571 Anchore CVE Medium libarchive-3.3.3-5.el8
CVE-2023-34969 Anchore CVE Medium dbus-daemon-1:1.12.8-24.el8
CVE-2023-34969 Anchore CVE Medium dbus-common-1:1.12.8-24.el8
CVE-2023-34969 Anchore CVE Medium dbus-libs-1:1.12.8-24.el8
CVE-2023-34969 Anchore CVE Medium dbus-1:1.12.8-24.el8
CVE-2023-34969 Anchore CVE Medium dbus-tools-1:1.12.8-24.el8
CVE-2023-27043 Anchore CVE Medium platform-python-3.6.8-51.el8_8.1
CVE-2007-4559 Anchore CVE Medium platform-python-3.6.8-51.el8_8.1
CVE-2007-4559 Anchore CVE Medium python3-libs-3.6.8-51.el8_8.1
CVE-2023-27043 Anchore CVE Medium python3-libs-3.6.8-51.el8_8.1
CVE-2023-36191 Anchore CVE Low sqlite-libs-3.26.0-18.el8_8
CVE-2023-36632 Anchore CVE Medium python3-libs-3.6.8-51.el8_8.1
CVE-2023-36632 Anchore CVE Medium platform-python-3.6.8-51.el8_8.1
CCE-85987-6 OSCAP Compliance Medium
CVE-2022-23990 Twistlock CVE Medium expat-2.2.5-11.el8
CVE-2021-35939 Twistlock CVE Medium rpm-4.14.3-26.el8
CVE-2021-35939 Twistlock CVE Medium python3-rpm-4.14.3-26.el8
CVE-2021-35939 Twistlock CVE Medium rpm-libs-4.14.3-26.el8
CVE-2021-35939 Twistlock CVE Medium rpm-build-libs-4.14.3-26.el8
CVE-2021-35938 Twistlock CVE Medium rpm-build-libs-4.14.3-26.el8
CVE-2021-35938 Twistlock CVE Medium rpm-libs-4.14.3-26.el8
CVE-2021-35938 Twistlock CVE Medium python3-rpm-4.14.3-26.el8
CVE-2021-35938 Twistlock CVE Medium rpm-4.14.3-26.el8
CVE-2021-35937 Twistlock CVE Medium rpm-4.14.3-26.el8
CVE-2021-35937 Twistlock CVE Medium rpm-build-libs-4.14.3-26.el8
CVE-2021-35937 Twistlock CVE Medium python3-rpm-4.14.3-26.el8
CVE-2021-35937 Twistlock CVE Medium rpm-libs-4.14.3-26.el8
CVE-2022-0235 Twistlock CVE Medium python3-cloud-what-1.28.36-2.el8
CVE-2022-0235 Twistlock CVE Medium subscription-manager-1.28.36-2.el8
CVE-2022-0235 Twistlock CVE Medium subscription-manager-rhsm-certificates-1.28.36-2.el8
CVE-2022-0235 Twistlock CVE Medium dnf-plugin-subscription-manager-1.28.36-2.el8
CVE-2022-0235 Twistlock CVE Medium python3-syspurpose-1.28.36-2.el8
CVE-2022-0235 Twistlock CVE Medium python3-subscription-manager-rhsm-1.28.36-2.el8
CVE-2023-29469 Twistlock CVE Medium python3-libxml2-2.9.7-16.el8
CVE-2023-29469 Twistlock CVE Medium libxml2-2.9.7-16.el8
CVE-2023-28484 Twistlock CVE Medium libxml2-2.9.7-16.el8
CVE-2023-28484 Twistlock CVE Medium python3-libxml2-2.9.7-16.el8
CVE-2023-27536 Twistlock CVE Medium curl-7.61.1-30.el8_8.2
CVE-2023-27536 Twistlock CVE Medium libcurl-7.61.1-30.el8_8.2
CVE-2020-21674 Twistlock CVE Low libarchive-3.3.3-5.el8
CVE-2020-35512 Twistlock CVE Low dbus-libs-1.12.8-24.el8
CVE-2020-35512 Twistlock CVE Low dbus-1.12.8-24.el8
CVE-2020-35512 Twistlock CVE Low dbus-daemon-1.12.8-24.el8
CVE-2020-35512 Twistlock CVE Low dbus-common-1.12.8-24.el8
CVE-2020-35512 Twistlock CVE Low dbus-tools-1.12.8-24.el8
CVE-2022-27943 Twistlock CVE Low libstdc++-8.5.0-18.el8
CVE-2022-27943 Twistlock CVE Low libgcc-8.5.0-18.el8
CVE-2019-16866 Twistlock CVE Low unbound-libs-1.16.2-5.el8
CVE-2019-16866 Twistlock CVE Low python3-unbound-1.16.2-5.el8
CVE-2019-8906 Twistlock CVE Low file-libs-5.33-24.el8
CVE-2019-8905 Twistlock CVE Low file-libs-5.33-24.el8
CVE-2023-27534 Twistlock CVE Low curl-7.61.1-30.el8_8.2
CVE-2023-27534 Twistlock CVE Low libcurl-7.61.1-30.el8_8.2
CVE-2021-20193 Twistlock CVE Low tar-1.30-9.el8
CVE-2019-9923 Twistlock CVE Low tar-1.30-9.el8
CVE-2019-14250 Twistlock CVE Low libstdc++-8.5.0-18.el8
CVE-2019-14250 Twistlock CVE Low libgcc-8.5.0-18.el8
CVE-2018-20657 Twistlock CVE Low libstdc++-8.5.0-18.el8
CVE-2018-20657 Twistlock CVE Low libgcc-8.5.0-18.el8
CVE-2018-1000880 Twistlock CVE Low libarchive-3.3.3-5.el8
CVE-2018-1000879 Twistlock CVE Low libarchive-3.3.3-5.el8
CVE-2019-9674 Twistlock CVE Low python3-libs-3.6.8-51.el8_8.1
CVE-2019-9674 Twistlock CVE Low platform-python-3.6.8-51.el8_8.1
CVE-2023-30630 Twistlock CVE Medium dmidecode-3.3-4.el8
CVE-2023-29491 Twistlock CVE Medium ncurses-libs-6.1-9.20180224.el8
CVE-2023-29491 Twistlock CVE Medium ncurses-base-6.1-9.20180224.el8
CVE-2023-34969 Twistlock CVE Medium dbus-libs-1.12.8-24.el8
CVE-2023-34969 Twistlock CVE Medium dbus-1.12.8-24.el8
CVE-2023-34969 Twistlock CVE Medium dbus-daemon-1.12.8-24.el8
CVE-2023-34969 Twistlock CVE Medium dbus-common-1.12.8-24.el8
CVE-2023-34969 Twistlock CVE Medium dbus-tools-1.12.8-24.el8
CVE-2023-28321 Twistlock CVE Medium libcurl-7.61.1-30.el8_8.2
CVE-2023-28321 Twistlock CVE Medium curl-7.61.1-30.el8_8.2
CVE-2023-29383 Twistlock CVE Medium util-linux-2.32.1-42.el8_8
CVE-2023-29383 Twistlock CVE Medium libsmartcols-2.32.1-42.el8_8
CVE-2023-29383 Twistlock CVE Medium libmount-2.32.1-42.el8_8
CVE-2023-29383 Twistlock CVE Medium libblkid-2.32.1-42.el8_8
CVE-2023-29383 Twistlock CVE Medium libfdisk-2.32.1-42.el8_8
CVE-2023-29383 Twistlock CVE Medium libuuid-2.32.1-42.el8_8
CVE-2023-30571 Twistlock CVE Medium libarchive-3.3.3-5.el8
CVE-2023-27043 Twistlock CVE Medium python3-libs-3.6.8-51.el8_8.1
CVE-2023-27043 Twistlock CVE Medium platform-python-3.6.8-51.el8_8.1
CVE-2023-2603 Twistlock CVE Medium libcap-2.48-4.el8
CVE-2023-2222 Twistlock CVE Medium gdb-gdbserver-8.2-19.el8
CVE-2023-2953 Twistlock CVE Low openldap-2.4.46-18.el8
CVE-2023-2650 Twistlock CVE Low openssl-libs-1.1.1k-9.el8_7
CVE-2023-2650 Twistlock CVE Low openssl-1.1.1k-9.el8_7
CVE-2023-32665 Twistlock CVE Low glib2-2.56.4-161.el8
CVE-2023-32611 Twistlock CVE Low glib2-2.56.4-161.el8
CVE-2023-29499 Twistlock CVE Low glib2-2.56.4-161.el8
CVE-2023-32636 Twistlock CVE Low glib2-2.56.4-161.el8
CVE-2023-2602 Twistlock CVE Low libcap-2.48-4.el8
CVE-2020-17049 Twistlock CVE Medium krb5-libs-1.18.2-25.el8_8
CVE-2018-20839 Twistlock CVE Medium systemd-239-74.el8_8.2
CVE-2018-20839 Twistlock CVE Medium systemd-pam-239-74.el8_8.2
CVE-2018-20839 Twistlock CVE Medium systemd-libs-239-74.el8_8.2
CVE-2019-19244 Twistlock CVE Low sqlite-libs-3.26.0-18.el8_8
CVE-2021-3997 Twistlock CVE Low systemd-libs-239-74.el8_8.2
CVE-2021-3997 Twistlock CVE Low systemd-pam-239-74.el8_8.2
CVE-2021-3997 Twistlock CVE Low systemd-239-74.el8_8.2
CVE-2019-9937 Twistlock CVE Low sqlite-libs-3.26.0-18.el8_8
CVE-2019-9936 Twistlock CVE Low sqlite-libs-3.26.0-18.el8_8
CVE-2023-36191 Twistlock CVE Low sqlite-libs-3.26.0-18.el8_8

VAT: https://vat.dso.mil/vat/image?imageName=beast-code/weapon-one/base-image&tag=0.3.2&branch=master
More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/beast-code/weapon-one/base-image/-/jobs/13726785

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the ~"Approval" label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications
  • Send approval request to Authorizing Official
  • Close issue after approval from Authorizing Official

Note: If the above approval process is rejected for any reason, the Approval label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Approval label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by Ghost User
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information