chore(findings): bitnami/kafka
Summary
bitnami/kafka has 19 new findings discovered during continuous monitoring.
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=bitnami/kafka&tag=4.0.0&branch=master
EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.
KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.
id | source | severity | package | impact | workaround | epss_score | kev |
---|---|---|---|---|---|---|---|
CVE-2024-8176 | Twistlock CVE | Low | expat-2.5.0-1+deb12u1 | 0.00749 | false | ||
CVE-2025-48734 | Twistlock CVE | Low | commons-beanutils_commons-beanutils-1.9.4 | 0.00212 | false | ||
CVE-2025-48924 | Twistlock CVE | Medium | org.apache.commons_commons-lang3-3.12.0 | 0.00185 | false | ||
CVE-2025-21587 | Twistlock CVE | Low | java-21.0.6 | 0.00070 | false | ||
CVE-2025-21587 | Twistlock CVE | Low | java-17.0.14 | 0.00070 | false | ||
CVE-2025-30698 | Twistlock CVE | Low | java-17.0.14 | 0.00063 | false | ||
CVE-2025-30698 | Twistlock CVE | Low | java-21.0.6 | 0.00063 | false | ||
CVE-2025-50106 | Anchore CVE | High | openjdk-21.0.6+7-LTS | 0.00056 | false | ||
CVE-2025-30749 | Anchore CVE | High | openjdk-21.0.6+7-LTS | 0.00056 | false | ||
CVE-2025-30691 | Twistlock CVE | Low | java-21.0.6 | 0.00047 | false | ||
CVE-2025-50059 | Anchore CVE | High | openjdk-21.0.6+7-LTS | 0.00042 | false | ||
CVE-2025-30754 | Anchore CVE | Medium | openjdk-21.0.6+7-LTS | 0.00035 | false | ||
eec438eed6560f1ea7792b726009538e | Anchore Compliance | Low | N/A | N/A | |||
e56b64c2a7d254d4174ecaed69899327 | Anchore Compliance | Critical | N/A | N/A | |||
c2e44319ae5b3b040044d8ae116d1c2f | Anchore Compliance | Low | N/A | N/A | |||
bcd159901fe47efddae5c095b4b0d7fd | Anchore Compliance | Low | N/A | N/A | |||
75d08d8c7b064bbd44f2f524c924d17b | Anchore Compliance | Low | N/A | N/A | |||
6329fe232b699ab5b4c9002b9f1b1f9e | Anchore Compliance | Critical | N/A | N/A | |||
463a9a24225c26f7a5bf3f38908e5cb3 | Anchore Compliance | Low | N/A | N/A |
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=bitnami/kafka&tag=4.0.0&branch=master
Tasks
Contributor:
-
Provide justifications for findings in the VAT (docs) -
Apply the StatusVerification label to this issue and wait for feedback
Iron Bank:
-
Review findings and justifications
Note: If the above process is rejected for any reason, the
Verification
label will be removed and the issue will be sent back toOpen
. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add theVerification
label.
Questions?
Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding
.
Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.