UNCLASSIFIED - NO CUI

Skip to content

chore(findings): tetrate/istio/istioctl

Summary

tetrate/istio/istioctl has 25 new findings discovered during continuous monitoring.

id source severity package
CVE-2022-30580 twistlock_cve High go-1.17.8b7
CVE-2022-32189 twistlock_cve High go-1.17.8b7
CVE-2022-30635 twistlock_cve High go-1.17.8b7
CVE-2022-30633 twistlock_cve High go-1.17.8b7
CVE-2022-30632 twistlock_cve High go-1.17.8b7
CVE-2022-30631 twistlock_cve High go-1.17.8b7
CVE-2022-30630 twistlock_cve High go-1.17.8b7
CVE-2022-28131 twistlock_cve High go-1.17.8b7
CVE-2022-32148 twistlock_cve Medium go-1.17.8b7
CVE-2022-1705 twistlock_cve Medium go-1.17.8b7
CVE-2022-1962 twistlock_cve Medium go-1.17.8b7
PRISMA-2022-0270 twistlock_cve Medium github.com/golang-jwt/jwt/v4-v4.0.0
CVE-2022-36055 twistlock_cve Medium helm.sh/helm/v3-v3.7.1
CVE-2022-29162 twistlock_cve Medium github.com/opencontainers/runc-v1.0.2
CVE-2021-43784 twistlock_cve Medium github.com/opencontainers/runc-v1.0.2
CVE-2022-30629 twistlock_cve Low go-1.17.8b7
GHSA-qq97-vm5h-rrhg twistlock_cve Low github.com/docker/distribution-v2.7.1
GHSA-77vh-xpmg-72qh twistlock_cve Low github.com/opencontainers/image-spec-v1.0.1
GHSA-7774-7vr3-cc8j anchore_cve High istio.io/istio-(devel)
GHSA-hqxw-mm44-gc4r anchore_cve High istio.io/istio-(devel)
GHSA-f3fp-gc8g-vw66 anchore_cve Medium github.com/opencontainers/runc-v1.0.2
GHSA-856q-xv3c-7f2f anchore_cve High istio.io/istio-(devel)
GHSA-xwx5-5c9g-x68x anchore_cve Medium istio.io/istio-(devel)
CVE-2022-27664 twistlock_cve High go-1.17.8b7
GHSA-rc4r-wh2q-q6c4 anchore_cve Medium github.com/moby/moby-v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible

VAT: https://vat.dso.mil/vat/container/21785?branch=master
More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/tetrate/istio/1.12/istioctl/-/jobs/14365764

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the ~"Hardening::Approval" label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications
  • Send approval request to Authorizing Official
  • Close issue after approval from Authorizing Official

Note: If the above approval process is rejected for any reason, the Approval label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Approval label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by Ghost User
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information