Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address CVEs for Request Logger Image from Twistlock Reports #2960

Closed
axsaucedo opened this issue Feb 16, 2021 · 0 comments · Fixed by #2977
Closed

Address CVEs for Request Logger Image from Twistlock Reports #2960

axsaucedo opened this issue Feb 16, 2021 · 0 comments · Fixed by #2977
Assignees
Labels
bug triage Needs to be triaged and prioritised accordingly

Comments

@axsaucedo
Copy link
Contributor

Actionable Vulnerabilities: Implies there is a fixed version available for vulnerable package.

Severity   CVSS       Type       CVE ID               Package                                       Version                                  status                                   Twistlock Severity   Link                                                                                                

P2         8.1        image      CVE-2020-8265        node                                          10.21.0                                  fixed in 10.23.1                         high                 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8265                                      
P2         7.8        image      CVE-2020-8252        node                                          10.21.0                                  fixed in 14.9.0, 12.18.4, 10.22.1        high                 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8252                                      
P2         7.5        image      CVE-2020-9490        httpd                                         2.4.37                                   fixed in 2.4.46                          high                 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-9490                                      
P2         7.3        nodejs     CVE-2020-8116        dot-prop                                      4.2.0                                    fixed in 5.1.1, 4.2.1                    high                 https://www.npmjs.com/advisories                                                                    
P2         7.3        nodejs     CVE-2020-7788        ini                                           1.3.5                                    fixed in 1.3.6                           low                  https://www.npmjs.com/advisories                                                                    
P3         6.5        image      CVE-2020-8287        node                                          10.21.0                                  fixed in 10.23.1                         medium               https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8287                                      
P3         4.4        nodejs     CVE-2020-15095       npm                                           6.14.4                                   fixed in 6.14.6                          low                  https://www.npmjs.com/advisories                                                                    
P4         1          nodejs     GHSA-xgh6-85xh-479p  npm-user-validate                             1.0.0                                    fixed in 1.0.1                           low                  https://www.npmjs.com/advisories                                                                    
P3         0          python     PRISMA-2021-0020     click                                         7.1.2                                    fixed in 8.0.0                           medium           

Summary

P1         P2         P3         P4        
0          5          3          1         
@axsaucedo axsaucedo added bug triage Needs to be triaged and prioritised accordingly labels Feb 16, 2021
@axsaucedo axsaucedo self-assigned this Feb 18, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug triage Needs to be triaged and prioritised accordingly
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant