From 0293ab43a9d46303771fbf9d66e3509148ce1085 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 15 Jan 2023 02:47:03 +0000 Subject: [PATCH] [Bot] docs: Update Snyk reports (#11985) Signed-off-by: CI Signed-off-by: CI Co-authored-by: CI Signed-off-by: emirot --- docs/snyk/index.md | 46 +- docs/snyk/master/argocd-iac-install.html | 66 +- .../master/argocd-iac-namespace-install.html | 2 +- docs/snyk/master/argocd-test.html | 94 +-- .../master/ghcr.io_dexidp_dex_v2.35.3.html | 2 +- docs/snyk/master/haproxy_2.6.2-alpine.html | 2 +- .../quay.io_argoproj_argocd_latest.html | 246 ++++++- docs/snyk/master/redis_7.0.5-alpine.html | 646 ------------------ docs/snyk/master/redis_7.0.7-alpine.html | 492 +++++++++++++ docs/snyk/v2.3.12/argocd-iac-install.html | 2 +- .../v2.3.12/argocd-iac-namespace-install.html | 2 +- docs/snyk/v2.3.12/argocd-test.html | 2 +- .../v2.3.12/ghcr.io_dexidp_dex_v2.35.3.html | 2 +- docs/snyk/v2.3.12/haproxy_2.0.29-alpine.html | 2 +- ...argoproj_argocd-applicationset_v0.4.1.html | 4 +- .../quay.io_argoproj_argocd_v2.3.12.html | 234 ++++++- docs/snyk/v2.3.12/redis_6.2.7-alpine.html | 2 +- docs/snyk/v2.4.18/argocd-iac-install.html | 2 +- .../v2.4.18/argocd-iac-namespace-install.html | 2 +- docs/snyk/v2.4.18/argocd-test.html | 2 +- .../v2.4.18/ghcr.io_dexidp_dex_v2.35.3.html | 2 +- docs/snyk/v2.4.18/haproxy_2.0.29-alpine.html | 2 +- .../quay.io_argoproj_argocd_v2.4.18.html | 234 ++++++- docs/snyk/v2.4.18/redis_7.0.4-alpine.html | 2 +- docs/snyk/v2.5.5/redis_7.0.5-alpine.html | 646 ------------------ .../argocd-iac-install.html | 2 +- .../argocd-iac-namespace-install.html | 2 +- docs/snyk/{v2.5.5 => v2.5.6}/argocd-test.html | 111 +-- .../ghcr.io_dexidp_dex_v2.35.3.html | 2 +- .../haproxy_2.6.2-alpine.html | 2 +- .../quay.io_argoproj_argocd_v2.5.6.html} | 497 +++++++------- docs/snyk/v2.5.6/redis_7.0.7-alpine.html | 492 +++++++++++++ docs/snyk/v2.6.0-rc2/redis_7.0.5-alpine.html | 646 ------------------ .../argocd-iac-install.html | 66 +- .../argocd-iac-namespace-install.html | 2 +- .../argocd-test.html | 94 +-- .../ghcr.io_dexidp_dex_v2.35.3.html | 2 +- .../haproxy_2.6.2-alpine.html | 2 +- .../quay.io_argoproj_argocd_v2.6.0-rc3.html} | 457 ++++++++----- docs/snyk/v2.6.0-rc3/redis_7.0.7-alpine.html | 492 +++++++++++++ 40 files changed, 2808 insertions(+), 2799 deletions(-) delete mode 100644 docs/snyk/master/redis_7.0.5-alpine.html create mode 100644 docs/snyk/master/redis_7.0.7-alpine.html delete mode 100644 docs/snyk/v2.5.5/redis_7.0.5-alpine.html rename docs/snyk/{v2.5.5 => v2.5.6}/argocd-iac-install.html (99%) rename docs/snyk/{v2.5.5 => v2.5.6}/argocd-iac-namespace-install.html (99%) rename docs/snyk/{v2.5.5 => v2.5.6}/argocd-test.html (96%) rename docs/snyk/{v2.6.0-rc2 => v2.5.6}/ghcr.io_dexidp_dex_v2.35.3.html (99%) rename docs/snyk/{v2.5.5 => v2.5.6}/haproxy_2.6.2-alpine.html (99%) rename docs/snyk/{v2.5.5/quay.io_argoproj_argocd_v2.5.5.html => v2.5.6/quay.io_argoproj_argocd_v2.5.6.html} (91%) create mode 100644 docs/snyk/v2.5.6/redis_7.0.7-alpine.html delete mode 100644 docs/snyk/v2.6.0-rc2/redis_7.0.5-alpine.html rename docs/snyk/{v2.6.0-rc2 => v2.6.0-rc3}/argocd-iac-install.html (98%) rename docs/snyk/{v2.6.0-rc2 => v2.6.0-rc3}/argocd-iac-namespace-install.html (99%) rename docs/snyk/{v2.6.0-rc2 => v2.6.0-rc3}/argocd-test.html (96%) rename docs/snyk/{v2.5.5 => v2.6.0-rc3}/ghcr.io_dexidp_dex_v2.35.3.html (99%) rename docs/snyk/{v2.6.0-rc2 => v2.6.0-rc3}/haproxy_2.6.2-alpine.html (99%) rename docs/snyk/{v2.6.0-rc2/quay.io_argoproj_argocd_v2.6.0-rc2.html => v2.6.0-rc3/quay.io_argoproj_argocd_v2.6.0-rc3.html} (89%) create mode 100644 docs/snyk/v2.6.0-rc3/redis_7.0.7-alpine.html diff --git a/docs/snyk/index.md b/docs/snyk/index.md index bc529f66233da..4f9343486a010 100644 --- a/docs/snyk/index.md +++ b/docs/snyk/index.md @@ -14,39 +14,39 @@ recent minor releases. | | Critical | High | Medium | Low | |---:|:--------:|:----:|:------:|:---:| | [go.mod](master/argocd-test.html) | 0 | 0 | 1 | 0 | -| [ui/yarn.lock](master/argocd-test.html) | 0 | 1 | 0 | 0 | +| [ui/yarn.lock](master/argocd-test.html) | 0 | 0 | 0 | 0 | | [dex:v2.35.3](master/ghcr.io_dexidp_dex_v2.35.3.html) | 0 | 0 | 0 | 0 | | [haproxy:2.6.2-alpine](master/haproxy_2.6.2-alpine.html) | 0 | 0 | 0 | 0 | -| [argocd:latest](master/quay.io_argoproj_argocd_latest.html) | 0 | 0 | 1 | 14 | -| [redis:7.0.5-alpine](master/redis_7.0.5-alpine.html) | 0 | 1 | 0 | 0 | +| [argocd:latest](master/quay.io_argoproj_argocd_latest.html) | 0 | 0 | 2 | 14 | +| [redis:7.0.7-alpine](master/redis_7.0.7-alpine.html) | 0 | 0 | 0 | 0 | | [install.yaml](master/argocd-iac-install.html) | - | - | - | - | | [namespace-install.yaml](master/argocd-iac-namespace-install.html) | - | - | - | - | -### v2.6.0-rc2 +### v2.6.0-rc3 | | Critical | High | Medium | Low | |---:|:--------:|:----:|:------:|:---:| -| [go.mod](v2.6.0-rc2/argocd-test.html) | 0 | 0 | 1 | 0 | -| [ui/yarn.lock](v2.6.0-rc2/argocd-test.html) | 0 | 1 | 0 | 0 | -| [dex:v2.35.3](v2.6.0-rc2/ghcr.io_dexidp_dex_v2.35.3.html) | 0 | 0 | 0 | 0 | -| [haproxy:2.6.2-alpine](v2.6.0-rc2/haproxy_2.6.2-alpine.html) | 0 | 0 | 0 | 0 | -| [argocd:v2.6.0-rc2](v2.6.0-rc2/quay.io_argoproj_argocd_v2.6.0-rc2.html) | 0 | 0 | 3 | 14 | -| [redis:7.0.5-alpine](v2.6.0-rc2/redis_7.0.5-alpine.html) | 0 | 1 | 0 | 0 | -| [install.yaml](v2.6.0-rc2/argocd-iac-install.html) | - | - | - | - | -| [namespace-install.yaml](v2.6.0-rc2/argocd-iac-namespace-install.html) | - | - | - | - | +| [go.mod](v2.6.0-rc3/argocd-test.html) | 0 | 0 | 1 | 0 | +| [ui/yarn.lock](v2.6.0-rc3/argocd-test.html) | 0 | 0 | 0 | 0 | +| [dex:v2.35.3](v2.6.0-rc3/ghcr.io_dexidp_dex_v2.35.3.html) | 0 | 0 | 0 | 0 | +| [haproxy:2.6.2-alpine](v2.6.0-rc3/haproxy_2.6.2-alpine.html) | 0 | 0 | 0 | 0 | +| [argocd:v2.6.0-rc3](v2.6.0-rc3/quay.io_argoproj_argocd_v2.6.0-rc3.html) | 0 | 0 | 2 | 14 | +| [redis:7.0.7-alpine](v2.6.0-rc3/redis_7.0.7-alpine.html) | 0 | 0 | 0 | 0 | +| [install.yaml](v2.6.0-rc3/argocd-iac-install.html) | - | - | - | - | +| [namespace-install.yaml](v2.6.0-rc3/argocd-iac-namespace-install.html) | - | - | - | - | -### v2.5.5 +### v2.5.6 | | Critical | High | Medium | Low | |---:|:--------:|:----:|:------:|:---:| -| [go.mod](v2.5.5/argocd-test.html) | 0 | 0 | 4 | 0 | -| [ui/yarn.lock](v2.5.5/argocd-test.html) | 0 | 1 | 3 | 0 | -| [dex:v2.35.3](v2.5.5/ghcr.io_dexidp_dex_v2.35.3.html) | 0 | 0 | 0 | 0 | -| [haproxy:2.6.2-alpine](v2.5.5/haproxy_2.6.2-alpine.html) | 0 | 0 | 0 | 0 | -| [argocd:v2.5.5](v2.5.5/quay.io_argoproj_argocd_v2.5.5.html) | 0 | 0 | 4 | 14 | -| [redis:7.0.5-alpine](v2.5.5/redis_7.0.5-alpine.html) | 0 | 1 | 0 | 0 | -| [install.yaml](v2.5.5/argocd-iac-install.html) | - | - | - | - | -| [namespace-install.yaml](v2.5.5/argocd-iac-namespace-install.html) | - | - | - | - | +| [go.mod](v2.5.6/argocd-test.html) | 0 | 0 | 4 | 0 | +| [ui/yarn.lock](v2.5.6/argocd-test.html) | 0 | 0 | 3 | 0 | +| [dex:v2.35.3](v2.5.6/ghcr.io_dexidp_dex_v2.35.3.html) | 0 | 0 | 0 | 0 | +| [haproxy:2.6.2-alpine](v2.5.6/haproxy_2.6.2-alpine.html) | 0 | 0 | 0 | 0 | +| [argocd:v2.5.6](v2.5.6/quay.io_argoproj_argocd_v2.5.6.html) | 0 | 0 | 2 | 14 | +| [redis:7.0.7-alpine](v2.5.6/redis_7.0.7-alpine.html) | 0 | 0 | 0 | 0 | +| [install.yaml](v2.5.6/argocd-iac-install.html) | - | - | - | - | +| [namespace-install.yaml](v2.5.6/argocd-iac-namespace-install.html) | - | - | - | - | ### v2.4.18 @@ -56,7 +56,7 @@ recent minor releases. | [ui/yarn.lock](v2.4.18/argocd-test.html) | 0 | 1 | 3 | 0 | | [dex:v2.35.3](v2.4.18/ghcr.io_dexidp_dex_v2.35.3.html) | 0 | 0 | 0 | 0 | | [haproxy:2.0.29-alpine](v2.4.18/haproxy_2.0.29-alpine.html) | 0 | 0 | 0 | 0 | -| [argocd:v2.4.18](v2.4.18/quay.io_argoproj_argocd_v2.4.18.html) | 0 | 0 | 4 | 14 | +| [argocd:v2.4.18](v2.4.18/quay.io_argoproj_argocd_v2.4.18.html) | 0 | 0 | 5 | 14 | | [redis:7.0.4-alpine](v2.4.18/redis_7.0.4-alpine.html) | 0 | 0 | 0 | 0 | | [install.yaml](v2.4.18/argocd-iac-install.html) | - | - | - | - | | [namespace-install.yaml](v2.4.18/argocd-iac-namespace-install.html) | - | - | - | - | @@ -70,7 +70,7 @@ recent minor releases. | [dex:v2.35.3](v2.3.12/ghcr.io_dexidp_dex_v2.35.3.html) | 0 | 0 | 0 | 0 | | [haproxy:2.0.29-alpine](v2.3.12/haproxy_2.0.29-alpine.html) | 0 | 0 | 0 | 0 | | [argocd-applicationset:v0.4.1](v2.3.12/quay.io_argoproj_argocd-applicationset_v0.4.1.html) | 0 | 4 | 38 | 29 | -| [argocd:v2.3.12](v2.3.12/quay.io_argoproj_argocd_v2.3.12.html) | 0 | 0 | 4 | 14 | +| [argocd:v2.3.12](v2.3.12/quay.io_argoproj_argocd_v2.3.12.html) | 0 | 0 | 5 | 14 | | [redis:6.2.7-alpine](v2.3.12/redis_6.2.7-alpine.html) | 0 | 1 | 0 | 0 | | [install.yaml](v2.3.12/argocd-iac-install.html) | - | - | - | - | | [namespace-install.yaml](v2.3.12/argocd-iac-namespace-install.html) | - | - | - | - | diff --git a/docs/snyk/master/argocd-iac-install.html b/docs/snyk/master/argocd-iac-install.html index 4eb052d55f1ae..5276d11ccd4b1 100644 --- a/docs/snyk/master/argocd-iac-install.html +++ b/docs/snyk/master/argocd-iac-install.html @@ -456,7 +456,7 @@

Snyk test report

-

January 8th 2023, 12:17:19 am

+

January 15th 2023, 12:17:42 am

Scanned the following path: @@ -507,7 +507,7 @@

Role with dangerous permissions

  • - Line number: 15180 + Line number: 15177
  • @@ -553,7 +553,7 @@

    Role with dangerous permissions

  • - Line number: 15257 + Line number: 15254
  • @@ -599,7 +599,7 @@

    Role with dangerous permissions

  • - Line number: 15285 + Line number: 15282
  • @@ -645,7 +645,7 @@

    Role with dangerous permissions

  • - Line number: 15329 + Line number: 15326
  • @@ -691,7 +691,7 @@

    Role with dangerous permissions

  • - Line number: 15311 + Line number: 15308
  • @@ -737,7 +737,7 @@

    Role with dangerous permissions

  • - Line number: 15345 + Line number: 15342
  • @@ -789,7 +789,7 @@

    Container could be running with outdated image

  • - Line number: 16349 + Line number: 16346
  • @@ -847,7 +847,7 @@

    Container has no CPU limit

  • - Line number: 15812 + Line number: 15809
  • @@ -905,7 +905,7 @@

    Container has no CPU limit

  • - Line number: 15985 + Line number: 15982
  • @@ -963,7 +963,7 @@

    Container has no CPU limit

  • - Line number: 15951 + Line number: 15948
  • @@ -1021,7 +1021,7 @@

    Container has no CPU limit

  • - Line number: 16041 + Line number: 16038
  • @@ -1079,7 +1079,7 @@

    Container has no CPU limit

  • - Line number: 16115 + Line number: 16112
  • @@ -1137,7 +1137,7 @@

    Container has no CPU limit

  • - Line number: 16349 + Line number: 16346
  • @@ -1195,7 +1195,7 @@

    Container has no CPU limit

  • - Line number: 16171 + Line number: 16168
  • @@ -1253,7 +1253,7 @@

    Container has no CPU limit

  • - Line number: 16434 + Line number: 16431
  • @@ -1311,7 +1311,7 @@

    Container has no CPU limit

  • - Line number: 16738 + Line number: 16735
  • @@ -1363,7 +1363,7 @@

    Container is running with multiple open ports

  • - Line number: 15965 + Line number: 15962
  • @@ -1419,7 +1419,7 @@

    Container is running with writable root filesystem

  • - Line number: 16125 + Line number: 16122
  • @@ -1471,7 +1471,7 @@

    Container is running without liveness probe

  • - Line number: 15812 + Line number: 15809
  • @@ -1523,7 +1523,7 @@

    Container is running without liveness probe

  • - Line number: 15951 + Line number: 15948
  • @@ -1575,7 +1575,7 @@

    Container is running without liveness probe

  • - Line number: 15985 + Line number: 15982
  • @@ -1627,7 +1627,7 @@

    Container is running without liveness probe

  • - Line number: 16115 + Line number: 16112
  • @@ -1679,7 +1679,7 @@

    Container is running without liveness probe

  • - Line number: 16349 + Line number: 16346
  • @@ -1737,7 +1737,7 @@

    Container is running without memory limit

  • - Line number: 15812 + Line number: 15809
  • @@ -1795,7 +1795,7 @@

    Container is running without memory limit

  • - Line number: 15951 + Line number: 15948
  • @@ -1853,7 +1853,7 @@

    Container is running without memory limit

  • - Line number: 15985 + Line number: 15982
  • @@ -1911,7 +1911,7 @@

    Container is running without memory limit

  • - Line number: 16041 + Line number: 16038
  • @@ -1969,7 +1969,7 @@

    Container is running without memory limit

  • - Line number: 16115 + Line number: 16112
  • @@ -2027,7 +2027,7 @@

    Container is running without memory limit

  • - Line number: 16349 + Line number: 16346
  • @@ -2085,7 +2085,7 @@

    Container is running without memory limit

  • - Line number: 16171 + Line number: 16168
  • @@ -2143,7 +2143,7 @@

    Container is running without memory limit

  • - Line number: 16434 + Line number: 16431
  • @@ -2201,7 +2201,7 @@

    Container is running without memory limit

  • - Line number: 16738 + Line number: 16735
  • diff --git a/docs/snyk/master/argocd-iac-namespace-install.html b/docs/snyk/master/argocd-iac-namespace-install.html index 076f3950d0a4a..2a4fb648beac9 100644 --- a/docs/snyk/master/argocd-iac-namespace-install.html +++ b/docs/snyk/master/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:17:30 am

    +

    January 15th 2023, 12:17:53 am

    Scanned the following path: diff --git a/docs/snyk/master/argocd-test.html b/docs/snyk/master/argocd-test.html index 2386077fd51c6..2ba2ac693843e 100644 --- a/docs/snyk/master/argocd-test.html +++ b/docs/snyk/master/argocd-test.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:14:52 am

    +

    January 15th 2023, 12:15:12 am

    Scanned the following paths: @@ -466,9 +466,9 @@

    Snyk test report

    -
    2 known vulnerabilities
    -
    117 vulnerable dependency paths
    -
    1729 dependencies
    +
    1 known vulnerabilities
    +
    116 vulnerable dependency paths
    +
    1728 dependencies
    @@ -476,90 +476,6 @@

    Snyk test report

    -
    -

    Prototype Poisoning

    -
    - -
    - high severity -
    - -
    - -
      -
    • - Package Manager: npm -
    • -
    • - Vulnerable module: - - qs -
    • - -
    • Introduced through: - - - argo-cd-ui@1.0.0, superagent@7.1.6 and others -
    • -
    - -
    - - -

    Detailed paths

    - -
      -
    • - Introduced through: - argo-cd-ui@1.0.0 - - superagent@7.1.6 - - formidable@2.0.1 - - qs@6.9.3 - - - -
    • -
    - -
    - -
    - -

    Overview

    -

    qs is a querystring parser that supports nesting and arrays, with a depth limit.

    -

    Affected versions of this package are vulnerable to Prototype Poisoning which allows attackers to cause a Node process to hang, processing an Array object whose prototype has been replaced by one with an excessive length value.

    -

    Note: In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000.

    -

    Details

    -

    Denial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its intended and legitimate users.

    -

    Unlike other vulnerabilities, DoS attacks usually do not aim at breaching security. Rather, they are focused on making websites and services unavailable to genuine users resulting in downtime.

    -

    One popular Denial of Service vulnerability is DDoS (a Distributed Denial of Service), an attack that attempts to clog network pipes to the system by generating a large volume of traffic from many machines.

    -

    When it comes to open source libraries, DoS vulnerabilities allow attackers to trigger such a crash or crippling of the service by using a flaw either in the application code or from the use of open source libraries.

    -

    Two common types of DoS vulnerabilities:

    -
      -
    • High CPU/Memory Consumption- An attacker sending crafted requests that could cause the system to take a disproportionate amount of time to process. For example, commons-fileupload:commons-fileupload.

      -
    • -
    • Crash - An attacker sending crafted requests that could cause the system to crash. For Example, npm ws package

      -
    • -
    -

    Remediation

    -

    Upgrade qs to version 6.2.4, 6.3.3, 6.4.1, 6.5.3, 6.6.1, 6.7.3, 6.8.3, 6.9.7, 6.10.3 or higher.

    -

    References

    - - -
    - - - -

    Denial of Service (DoS)

    diff --git a/docs/snyk/master/ghcr.io_dexidp_dex_v2.35.3.html b/docs/snyk/master/ghcr.io_dexidp_dex_v2.35.3.html index 02c4bb66b75c5..ce74b97e89933 100644 --- a/docs/snyk/master/ghcr.io_dexidp_dex_v2.35.3.html +++ b/docs/snyk/master/ghcr.io_dexidp_dex_v2.35.3.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:15:01 am

    +

    January 15th 2023, 12:15:26 am

    Scanned the following path: diff --git a/docs/snyk/master/haproxy_2.6.2-alpine.html b/docs/snyk/master/haproxy_2.6.2-alpine.html index 11987ad91c4e9..e514a7bdfa398 100644 --- a/docs/snyk/master/haproxy_2.6.2-alpine.html +++ b/docs/snyk/master/haproxy_2.6.2-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:15:06 am

    +

    January 15th 2023, 12:15:33 am

    Scanned the following path: diff --git a/docs/snyk/master/quay.io_argoproj_argocd_latest.html b/docs/snyk/master/quay.io_argoproj_argocd_latest.html index 3d45427db58da..ba8e0dc9c3445 100644 --- a/docs/snyk/master/quay.io_argoproj_argocd_latest.html +++ b/docs/snyk/master/quay.io_argoproj_argocd_latest.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:15:32 am

    +

    January 15th 2023, 12:16:02 am

    Scanned the following path: @@ -466,8 +466,8 @@

    Snyk test report

    -
    15 known vulnerabilities
    -
    91 vulnerable dependency paths
    +
    16 known vulnerabilities
    +
    102 vulnerable dependency paths
    162 dependencies
    @@ -655,6 +655,230 @@

    References

    More about this vulnerability

    +
    +
    +

    Integer Overflow or Wraparound

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + krb5/libk5crypto3 +
    • + +
    • Introduced through: + + docker-image|quay.io/argoproj/argocd@latest and krb5/libk5crypto3@1.19.2-2 + +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + krb5/libkrb5-3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + openssh/openssh-client@1:8.9p1-3ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 + + libssh/libssh-4@0.9.6-2build1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + meta-common-packages@meta + + krb5/libkrb5support0@1.19.2-2 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream krb5 package.

    +

    PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

    +

    Remediation

    +

    There is no fixed version for Ubuntu:22.04 krb5.

    +

    References

    + + +
    + + +

    CVE-2022-46908

    @@ -1012,7 +1236,7 @@

    Detailed paths

    Introduced through: docker-image|quay.io/argoproj/argocd@latest - openssh/openssh-client@1:8.9p1-3 + openssh/openssh-client@1:8.9p1-3ubuntu0.1 openssl/libssl3@3.0.2-0ubuntu1.7 @@ -1137,7 +1361,7 @@

    CVE-2021-41617

  • Introduced through: - docker-image|quay.io/argoproj/argocd@latest and openssh/openssh-client@1:8.9p1-3 + docker-image|quay.io/argoproj/argocd@latest and openssh/openssh-client@1:8.9p1-3ubuntu0.1
  • @@ -1152,7 +1376,7 @@

    Detailed paths

    Introduced through: docker-image|quay.io/argoproj/argocd@latest - openssh/openssh-client@1:8.9p1-3 + openssh/openssh-client@1:8.9p1-3ubuntu0.1 @@ -1213,7 +1437,7 @@

    Information Exposure

  • Introduced through: - docker-image|quay.io/argoproj/argocd@latest and openssh/openssh-client@1:8.9p1-3 + docker-image|quay.io/argoproj/argocd@latest and openssh/openssh-client@1:8.9p1-3ubuntu0.1
  • @@ -1228,7 +1452,7 @@

    Detailed paths

    Introduced through: docker-image|quay.io/argoproj/argocd@latest - openssh/openssh-client@1:8.9p1-3 + openssh/openssh-client@1:8.9p1-3ubuntu0.1 @@ -1654,7 +1878,7 @@

    Detailed paths

    Introduced through: docker-image|quay.io/argoproj/argocd@latest - openssh/openssh-client@1:8.9p1-3 + openssh/openssh-client@1:8.9p1-3ubuntu0.1 krb5/libgssapi-krb5-2@1.19.2-2 @@ -2352,7 +2576,7 @@

    References

    -

    Out-of-Bounds

    +

    Out-of-bounds Write

    diff --git a/docs/snyk/master/redis_7.0.5-alpine.html b/docs/snyk/master/redis_7.0.5-alpine.html deleted file mode 100644 index 3d93f26de9dcc..0000000000000 --- a/docs/snyk/master/redis_7.0.5-alpine.html +++ /dev/null @@ -1,646 +0,0 @@ - - - - - - - - - Snyk test report - - - - - - - - - -
    -
    -
    -
    - - - Snyk - Open Source Security - - - - - - - -
    -

    Snyk test report

    - -

    January 8th 2023, 12:15:39 am

    -
    -
    - Scanned the following path: -
      -
    • redis:7.0.5-alpine (apk)
    • -
    -
    - -
    -
    1 known vulnerabilities
    -
    9 vulnerable dependency paths
    -
    18 dependencies
    -
    -
    -
    -
    -
    - - - - - - - -
    Project docker-image|redis
    Path redis:7.0.5-alpine
    Package Manager apk
    -
    -
    -
    -
    -

    Improper Locking

    -
    - -
    - high severity -
    - -
    - -
      -
    • - Package Manager: alpine:3.17 -
    • -
    • - Vulnerable module: - - openssl/libcrypto3 -
    • - -
    • Introduced through: - - docker-image|redis@7.0.5-alpine and openssl/libcrypto3@3.0.7-r0 - -
    • -
    - -
    - - -

    Detailed paths

    - -
      -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libssl3@3.0.7-r0 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - .redis-rundeps@20221202.003022 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - apk-tools/apk-tools@2.12.10-r1 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - busybox/ssl_client@1.35.0-r29 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - .redis-rundeps@20221202.003022 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - apk-tools/apk-tools@2.12.10-r1 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - busybox/ssl_client@1.35.0-r29 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    - -
    - -
    - -

    NVD Description

    -

    Note: Versions mentioned in the description apply to the upstream openssl package. - See How to fix? for Alpine:3.17 relevant versions.

    -

    If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the -policy&#39; argument to the command line utilities or by calling either X509_VERIFY_PARAM_add0_policy()' or `X509_VERIFY_PARAM_set1_policies()' functions.

    -

    Remediation

    -

    Upgrade Alpine:3.17 openssl to version 3.0.7-r2 or higher.

    -

    References

    - - -
    - - - -
    -
    -
    -
    - - - diff --git a/docs/snyk/master/redis_7.0.7-alpine.html b/docs/snyk/master/redis_7.0.7-alpine.html new file mode 100644 index 0000000000000..71195452d4af2 --- /dev/null +++ b/docs/snyk/master/redis_7.0.7-alpine.html @@ -0,0 +1,492 @@ + + + + + + + + + Snyk test report + + + + + + + + + +
    +
    +
    +
    + + + Snyk - Open Source Security + + + + + + + +
    +

    Snyk test report

    + +

    January 15th 2023, 12:16:08 am

    +
    +
    + Scanned the following path: +
      +
    • redis:7.0.7-alpine (apk)
    • +
    +
    + +
    +
    0 known vulnerabilities
    +
    0 vulnerable dependency paths
    +
    18 dependencies
    +
    +
    +
    +
    +
    + + + + + + + +
    Project docker-image|redis
    Path redis:7.0.7-alpine
    Package Manager apk
    +
    +
    + No known vulnerabilities detected. +
    +
    + + + diff --git a/docs/snyk/v2.3.12/argocd-iac-install.html b/docs/snyk/v2.3.12/argocd-iac-install.html index 6595fc0fa9ce9..19191a1e04fde 100644 --- a/docs/snyk/v2.3.12/argocd-iac-install.html +++ b/docs/snyk/v2.3.12/argocd-iac-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:26:59 am

    +

    January 15th 2023, 12:26:51 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.12/argocd-iac-namespace-install.html b/docs/snyk/v2.3.12/argocd-iac-namespace-install.html index 3b2efca71e327..dcedf97a95bf9 100644 --- a/docs/snyk/v2.3.12/argocd-iac-namespace-install.html +++ b/docs/snyk/v2.3.12/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:27:39 am

    +

    January 15th 2023, 12:27:29 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.12/argocd-test.html b/docs/snyk/v2.3.12/argocd-test.html index de65d94e7a5a2..e12ff9c552c15 100644 --- a/docs/snyk/v2.3.12/argocd-test.html +++ b/docs/snyk/v2.3.12/argocd-test.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:24:52 am

    +

    January 15th 2023, 12:24:49 am

    Scanned the following paths: diff --git a/docs/snyk/v2.3.12/ghcr.io_dexidp_dex_v2.35.3.html b/docs/snyk/v2.3.12/ghcr.io_dexidp_dex_v2.35.3.html index f0c2cec323787..603c2f717f00b 100644 --- a/docs/snyk/v2.3.12/ghcr.io_dexidp_dex_v2.35.3.html +++ b/docs/snyk/v2.3.12/ghcr.io_dexidp_dex_v2.35.3.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:24:59 am

    +

    January 15th 2023, 12:24:55 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.12/haproxy_2.0.29-alpine.html b/docs/snyk/v2.3.12/haproxy_2.0.29-alpine.html index c719e9968ccac..d879763d51b4d 100644 --- a/docs/snyk/v2.3.12/haproxy_2.0.29-alpine.html +++ b/docs/snyk/v2.3.12/haproxy_2.0.29-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:25:02 am

    +

    January 15th 2023, 12:24:57 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.12/quay.io_argoproj_argocd-applicationset_v0.4.1.html b/docs/snyk/v2.3.12/quay.io_argoproj_argocd-applicationset_v0.4.1.html index 46361becbdbce..de939f689805a 100644 --- a/docs/snyk/v2.3.12/quay.io_argoproj_argocd-applicationset_v0.4.1.html +++ b/docs/snyk/v2.3.12/quay.io_argoproj_argocd-applicationset_v0.4.1.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:25:19 am

    +

    January 15th 2023, 12:25:16 am

    Scanned the following path: @@ -2171,6 +2171,7 @@

    References

  • FEDORA
  • CONFIRM
  • FEDORA
  • +
  • CONFIRM

  • @@ -2349,6 +2350,7 @@

    References

  • CONFIRM
  • FEDORA
  • GENTOO
  • +
  • CONFIRM

  • diff --git a/docs/snyk/v2.3.12/quay.io_argoproj_argocd_v2.3.12.html b/docs/snyk/v2.3.12/quay.io_argoproj_argocd_v2.3.12.html index 326da7f007d96..84ff014060fe4 100644 --- a/docs/snyk/v2.3.12/quay.io_argoproj_argocd_v2.3.12.html +++ b/docs/snyk/v2.3.12/quay.io_argoproj_argocd_v2.3.12.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:25:52 am

    +

    January 15th 2023, 12:25:48 am

    Scanned the following path: @@ -466,8 +466,8 @@

    Snyk test report

    -
    18 known vulnerabilities
    -
    97 vulnerable dependency paths
    +
    19 known vulnerabilities
    +
    108 vulnerable dependency paths
    162 dependencies
    @@ -763,6 +763,230 @@

    References

    More about this vulnerability

    +
    +
    +

    Integer Overflow or Wraparound

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + krb5/libk5crypto3 +
    • + +
    • Introduced through: + + docker-image|quay.io/argoproj/argocd@v2.3.12 and krb5/libk5crypto3@1.19.2-2 + +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + krb5/libkrb5-3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + openssh/openssh-client@1:8.9p1-3 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + + libssh/libssh-4@0.9.6-2build1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.12 + + meta-common-packages@meta + + krb5/libkrb5support0@1.19.2-2 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream krb5 package.

    +

    PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

    +

    Remediation

    +

    There is no fixed version for Ubuntu:22.04 krb5.

    +

    References

    + + +
    + + +

    CVE-2022-43552

    @@ -2597,7 +2821,7 @@

    References

    -

    Out-of-Bounds

    +

    Out-of-bounds Write

    diff --git a/docs/snyk/v2.3.12/redis_6.2.7-alpine.html b/docs/snyk/v2.3.12/redis_6.2.7-alpine.html index 9c30c34e1f53a..ef14fa075347b 100644 --- a/docs/snyk/v2.3.12/redis_6.2.7-alpine.html +++ b/docs/snyk/v2.3.12/redis_6.2.7-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:25:58 am

    +

    January 15th 2023, 12:25:55 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.18/argocd-iac-install.html b/docs/snyk/v2.4.18/argocd-iac-install.html index 4421f62da1df2..ceb182188d35e 100644 --- a/docs/snyk/v2.4.18/argocd-iac-install.html +++ b/docs/snyk/v2.4.18/argocd-iac-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:24:27 am

    +

    January 15th 2023, 12:24:24 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.18/argocd-iac-namespace-install.html b/docs/snyk/v2.4.18/argocd-iac-namespace-install.html index 5b309311377c5..37e9781b38dc0 100644 --- a/docs/snyk/v2.4.18/argocd-iac-namespace-install.html +++ b/docs/snyk/v2.4.18/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:24:39 am

    +

    January 15th 2023, 12:24:33 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.18/argocd-test.html b/docs/snyk/v2.4.18/argocd-test.html index 57595b2e44fe4..c456ece66c485 100644 --- a/docs/snyk/v2.4.18/argocd-test.html +++ b/docs/snyk/v2.4.18/argocd-test.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:22:47 am

    +

    January 15th 2023, 12:22:48 am

    Scanned the following paths: diff --git a/docs/snyk/v2.4.18/ghcr.io_dexidp_dex_v2.35.3.html b/docs/snyk/v2.4.18/ghcr.io_dexidp_dex_v2.35.3.html index 9b60725e48ffb..88da619efc432 100644 --- a/docs/snyk/v2.4.18/ghcr.io_dexidp_dex_v2.35.3.html +++ b/docs/snyk/v2.4.18/ghcr.io_dexidp_dex_v2.35.3.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:22:54 am

    +

    January 15th 2023, 12:22:54 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.18/haproxy_2.0.29-alpine.html b/docs/snyk/v2.4.18/haproxy_2.0.29-alpine.html index af487d5da77dd..1ed851d9bb85b 100644 --- a/docs/snyk/v2.4.18/haproxy_2.0.29-alpine.html +++ b/docs/snyk/v2.4.18/haproxy_2.0.29-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:23:00 am

    +

    January 15th 2023, 12:23:01 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.18/quay.io_argoproj_argocd_v2.4.18.html b/docs/snyk/v2.4.18/quay.io_argoproj_argocd_v2.4.18.html index ebd4e51c200b5..a296a9f60de8e 100644 --- a/docs/snyk/v2.4.18/quay.io_argoproj_argocd_v2.4.18.html +++ b/docs/snyk/v2.4.18/quay.io_argoproj_argocd_v2.4.18.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:23:21 am

    +

    January 15th 2023, 12:23:21 am

    Scanned the following path: @@ -466,8 +466,8 @@

    Snyk test report

    -
    18 known vulnerabilities
    -
    97 vulnerable dependency paths
    +
    19 known vulnerabilities
    +
    108 vulnerable dependency paths
    162 dependencies
    @@ -763,6 +763,230 @@

    References

    More about this vulnerability

    +
    +
    +

    Integer Overflow or Wraparound

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + krb5/libk5crypto3 +
    • + +
    • Introduced through: + + docker-image|quay.io/argoproj/argocd@v2.4.18 and krb5/libk5crypto3@1.19.2-2 + +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + krb5/libkrb5-3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + openssh/openssh-client@1:8.9p1-3 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + + libssh/libssh-4@0.9.6-2build1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.18 + + meta-common-packages@meta + + krb5/libkrb5support0@1.19.2-2 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream krb5 package.

    +

    PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

    +

    Remediation

    +

    There is no fixed version for Ubuntu:22.04 krb5.

    +

    References

    + + +
    + + +

    CVE-2022-43552

    @@ -2597,7 +2821,7 @@

    References

    -

    Out-of-Bounds

    +

    Out-of-bounds Write

    diff --git a/docs/snyk/v2.4.18/redis_7.0.4-alpine.html b/docs/snyk/v2.4.18/redis_7.0.4-alpine.html index 8bee7659e8709..9d85422df80d4 100644 --- a/docs/snyk/v2.4.18/redis_7.0.4-alpine.html +++ b/docs/snyk/v2.4.18/redis_7.0.4-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:23:27 am

    +

    January 15th 2023, 12:23:27 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.5/redis_7.0.5-alpine.html b/docs/snyk/v2.5.5/redis_7.0.5-alpine.html deleted file mode 100644 index bd94832ed9544..0000000000000 --- a/docs/snyk/v2.5.5/redis_7.0.5-alpine.html +++ /dev/null @@ -1,646 +0,0 @@ - - - - - - - - - Snyk test report - - - - - - - - - -
    -
    -
    -
    - - - Snyk - Open Source Security - - - - - - - -
    -

    Snyk test report

    - -

    January 8th 2023, 12:21:12 am

    -
    -
    - Scanned the following path: -
      -
    • redis:7.0.5-alpine (apk)
    • -
    -
    - -
    -
    1 known vulnerabilities
    -
    9 vulnerable dependency paths
    -
    18 dependencies
    -
    -
    -
    -
    -
    - - - - - - - -
    Project docker-image|redis
    Path redis:7.0.5-alpine
    Package Manager apk
    -
    -
    -
    -
    -

    Improper Locking

    -
    - -
    - high severity -
    - -
    - -
      -
    • - Package Manager: alpine:3.17 -
    • -
    • - Vulnerable module: - - openssl/libcrypto3 -
    • - -
    • Introduced through: - - docker-image|redis@7.0.5-alpine and openssl/libcrypto3@3.0.7-r0 - -
    • -
    - -
    - - -

    Detailed paths

    - -
      -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libssl3@3.0.7-r0 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - .redis-rundeps@20221202.003022 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - apk-tools/apk-tools@2.12.10-r1 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - busybox/ssl_client@1.35.0-r29 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - .redis-rundeps@20221202.003022 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - apk-tools/apk-tools@2.12.10-r1 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - busybox/ssl_client@1.35.0-r29 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    - -
    - -
    - -

    NVD Description

    -

    Note: Versions mentioned in the description apply to the upstream openssl package. - See How to fix? for Alpine:3.17 relevant versions.

    -

    If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the -policy&#39; argument to the command line utilities or by calling either X509_VERIFY_PARAM_add0_policy()' or `X509_VERIFY_PARAM_set1_policies()' functions.

    -

    Remediation

    -

    Upgrade Alpine:3.17 openssl to version 3.0.7-r2 or higher.

    -

    References

    - - -
    - - - -
    -
    -
    -
    - - - diff --git a/docs/snyk/v2.5.5/argocd-iac-install.html b/docs/snyk/v2.5.6/argocd-iac-install.html similarity index 99% rename from docs/snyk/v2.5.5/argocd-iac-install.html rename to docs/snyk/v2.5.6/argocd-iac-install.html index c90242dac9333..7e7f599632756 100644 --- a/docs/snyk/v2.5.5/argocd-iac-install.html +++ b/docs/snyk/v2.5.6/argocd-iac-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:22:18 am

    +

    January 15th 2023, 12:22:18 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.5/argocd-iac-namespace-install.html b/docs/snyk/v2.5.6/argocd-iac-namespace-install.html similarity index 99% rename from docs/snyk/v2.5.5/argocd-iac-namespace-install.html rename to docs/snyk/v2.5.6/argocd-iac-namespace-install.html index 8b434fbaca2fa..40eb7d604f077 100644 --- a/docs/snyk/v2.5.5/argocd-iac-namespace-install.html +++ b/docs/snyk/v2.5.6/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:22:29 am

    +

    January 15th 2023, 12:22:29 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.5/argocd-test.html b/docs/snyk/v2.5.6/argocd-test.html similarity index 96% rename from docs/snyk/v2.5.5/argocd-test.html rename to docs/snyk/v2.5.6/argocd-test.html index af78a0ed4ecec..ffd8a3ca4f6f7 100644 --- a/docs/snyk/v2.5.5/argocd-test.html +++ b/docs/snyk/v2.5.6/argocd-test.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:20:38 am

    +

    January 15th 2023, 12:20:48 am

    Scanned the following paths: @@ -466,9 +466,9 @@

    Snyk test report

    -
    8 known vulnerabilities
    -
    131 vulnerable dependency paths
    -
    1721 dependencies
    +
    7 known vulnerabilities
    +
    129 vulnerable dependency paths
    +
    1720 dependencies
    @@ -476,107 +476,6 @@

    Snyk test report

    -
    -

    Prototype Poisoning

    -
    - -
    - high severity -
    - -
    - -
      -
    • - Package Manager: npm -
    • -
    • - Vulnerable module: - - qs -
    • - -
    • Introduced through: - - - argo-cd-ui@1.0.0, git-url-parse@11.6.0 and others -
    • -
    - -
    - - -

    Detailed paths

    - -
      -
    • - Introduced through: - argo-cd-ui@1.0.0 - - git-url-parse@11.6.0 - - git-up@4.0.5 - - parse-url@6.0.5 - - parse-path@4.0.4 - - qs@6.10.1 - - - -
    • -
    • - Introduced through: - argo-cd-ui@1.0.0 - - superagent@7.1.6 - - formidable@2.0.1 - - qs@6.9.3 - - - -
    • -
    - -
    - -
    - -

    Overview

    -

    qs is a querystring parser that supports nesting and arrays, with a depth limit.

    -

    Affected versions of this package are vulnerable to Prototype Poisoning which allows attackers to cause a Node process to hang, processing an Array object whose prototype has been replaced by one with an excessive length value.

    -

    Note: In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000.

    -

    Details

    -

    Denial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its intended and legitimate users.

    -

    Unlike other vulnerabilities, DoS attacks usually do not aim at breaching security. Rather, they are focused on making websites and services unavailable to genuine users resulting in downtime.

    -

    One popular Denial of Service vulnerability is DDoS (a Distributed Denial of Service), an attack that attempts to clog network pipes to the system by generating a large volume of traffic from many machines.

    -

    When it comes to open source libraries, DoS vulnerabilities allow attackers to trigger such a crash or crippling of the service by using a flaw either in the application code or from the use of open source libraries.

    -

    Two common types of DoS vulnerabilities:

    -
      -
    • High CPU/Memory Consumption- An attacker sending crafted requests that could cause the system to take a disproportionate amount of time to process. For example, commons-fileupload:commons-fileupload.

      -
    • -
    • Crash - An attacker sending crafted requests that could cause the system to crash. For Example, npm ws package

      -
    • -
    -

    Remediation

    -

    Upgrade qs to version 6.2.4, 6.3.3, 6.4.1, 6.5.3, 6.6.1, 6.7.3, 6.8.3, 6.9.7, 6.10.3 or higher.

    -

    References

    - - -
    - - - -

    Server-side Request Forgery (SSRF)

    diff --git a/docs/snyk/v2.6.0-rc2/ghcr.io_dexidp_dex_v2.35.3.html b/docs/snyk/v2.5.6/ghcr.io_dexidp_dex_v2.35.3.html similarity index 99% rename from docs/snyk/v2.6.0-rc2/ghcr.io_dexidp_dex_v2.35.3.html rename to docs/snyk/v2.5.6/ghcr.io_dexidp_dex_v2.35.3.html index 23110f3579f2b..03338841e411d 100644 --- a/docs/snyk/v2.6.0-rc2/ghcr.io_dexidp_dex_v2.35.3.html +++ b/docs/snyk/v2.5.6/ghcr.io_dexidp_dex_v2.35.3.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:17:55 am

    +

    January 15th 2023, 12:20:54 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.5/haproxy_2.6.2-alpine.html b/docs/snyk/v2.5.6/haproxy_2.6.2-alpine.html similarity index 99% rename from docs/snyk/v2.5.5/haproxy_2.6.2-alpine.html rename to docs/snyk/v2.5.6/haproxy_2.6.2-alpine.html index 63861ba738b66..d7d3bac1ca21b 100644 --- a/docs/snyk/v2.5.5/haproxy_2.6.2-alpine.html +++ b/docs/snyk/v2.5.6/haproxy_2.6.2-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:20:48 am

    +

    January 15th 2023, 12:20:57 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.5/quay.io_argoproj_argocd_v2.5.5.html b/docs/snyk/v2.5.6/quay.io_argoproj_argocd_v2.5.6.html similarity index 91% rename from docs/snyk/v2.5.5/quay.io_argoproj_argocd_v2.5.5.html rename to docs/snyk/v2.5.6/quay.io_argoproj_argocd_v2.5.6.html index d4bb3d96041c9..e9a87c5c3211f 100644 --- a/docs/snyk/v2.5.5/quay.io_argoproj_argocd_v2.5.5.html +++ b/docs/snyk/v2.5.6/quay.io_argoproj_argocd_v2.5.6.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,18 +456,18 @@

    Snyk test report

    -

    January 8th 2023, 12:21:08 am

    +

    January 15th 2023, 12:21:17 am

    Scanned the following path:
      -
    • quay.io/argoproj/argocd:v2.5.5/argoproj/argocd (deb)
    • +
    • quay.io/argoproj/argocd:v2.5.6/argoproj/argocd (deb)
    -
    18 known vulnerabilities
    -
    97 vulnerable dependency paths
    +
    16 known vulnerabilities
    +
    102 vulnerable dependency paths
    162 dependencies
    @@ -477,7 +477,7 @@

    Snyk test report

    - + @@ -507,7 +507,7 @@

    Off-by-one Error

  • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and systemd/libsystemd0@249.11-0ubuntu3.6 + docker-image|quay.io/argoproj/argocd@v2.5.6 and systemd/libsystemd0@249.11-0ubuntu3.6
  • @@ -520,7 +520,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 systemd/libsystemd0@249.11-0ubuntu3.6 @@ -529,7 +529,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 apt@2.4.8 @@ -540,7 +540,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 procps/libprocps8@2:3.3.17-6ubuntu2 @@ -551,7 +551,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 util-linux@2.37.2-4ubuntu3 @@ -562,7 +562,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 util-linux/bsdutils@1:2.37.2-4ubuntu3 @@ -573,7 +573,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 apt@2.4.8 @@ -586,7 +586,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 systemd/libudev1@249.11-0ubuntu3.6 @@ -595,7 +595,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 libfido2/libfido2-1@1.10.0-1 @@ -606,7 +606,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 util-linux@2.37.2-4ubuntu3 @@ -617,7 +617,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 apt@2.4.8 @@ -673,12 +673,12 @@

      Integer Overflow or Wraparound

    • Vulnerable module: - libksba/libksba8 + krb5/libk5crypto3
    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and libksba/libksba8@1.6.0-2ubuntu0.1 + docker-image|quay.io/argoproj/argocd@v2.5.6 and krb5/libk5crypto3@1.19.2-2
    @@ -691,185 +691,161 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 - libksba/libksba8@1.6.0-2ubuntu0.1 + krb5/libk5crypto3@1.19.2-2
    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 - gnupg2/dirmngr@2.2.27-3ubuntu2.1 + adduser@3.118ubuntu5 - libksba/libksba8@1.6.0-2ubuntu0.1 + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2
    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 - gnupg2/gnupg@2.2.27-3ubuntu2.1 + adduser@3.118ubuntu5 - gnupg2/gnupg-utils@2.2.27-3ubuntu2.1 + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 - libksba/libksba8@1.6.0-2ubuntu0.1 + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2
    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 - gnupg2/gnupg@2.2.27-3ubuntu2.1 + krb5/libkrb5-3@1.19.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.6 - gnupg2/gpgsm@2.2.27-3ubuntu2.1 + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 - libksba/libksba8@1.6.0-2ubuntu0.1 + krb5/libkrb5-3@1.19.2-2
    • -
    - - - -
    - -

    NVD Description

    -

    Note: Versions mentioned in the description apply to the upstream libksba package. - See How to fix? for Ubuntu:22.04 relevant versions.

    -

    Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.

    -

    Remediation

    -

    Upgrade Ubuntu:22.04 libksba to version 1.6.0-2ubuntu0.2 or higher.

    -

    References

    - - -
    - - - - -
    -

    CVE-2022-43552

    -
    - -
    - medium severity -
    - -
    - -
      -
    • - Package Manager: ubuntu:22.04 -
    • -
    • - Vulnerable module: - - curl/libcurl3-gnutls -
    • - -
    • Introduced through: - - - docker-image|quay.io/argoproj/argocd@v2.5.5, git@1:2.34.1-1ubuntu1.5 and others -
    • -
    - -
    - +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.6 + + krb5/libgssapi-krb5-2@1.19.2-2 + + -

    Detailed paths

    +
  • +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.6 + + openssh/openssh-client@1:8.9p1-3 + + krb5/libgssapi-krb5-2@1.19.2-2 + + -
      +
    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 + + krb5/libgssapi-krb5-2@1.19.2-2
    • -
    - -
  • - -
    - -

    NVD Description

    -

    This vulnerability has not been analyzed by NVD yet.

    -

    Remediation

    -

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.7 or higher.

    -

    References

    - - -
    - - - -
    -
    -

    Cleartext Transmission of Sensitive Information

    -
    - -
    - medium severity -
    - -
    - -
      -
    • - Package Manager: ubuntu:22.04 -
    • -
    • - Vulnerable module: - - curl/libcurl3-gnutls -
    • - -
    • Introduced through: - - - docker-image|quay.io/argoproj/argocd@v2.5.5, git@1:2.34.1-1ubuntu1.5 and others -
    • -
    - -
    - +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.6 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 + + libssh/libssh-4@0.9.6-2build1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + -

    Detailed paths

    +
  • +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.6 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + -
      +
    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 - git@1:2.34.1-1ubuntu1.5 + meta-common-packages@meta - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + krb5/libkrb5support0@1.19.2-2 @@ -881,23 +857,26 @@

      Detailed paths


      NVD Description

      -

      Note: Versions mentioned in the description apply to the upstream curl package. - See How to fix? for Ubuntu:22.04 relevant versions.

      -

      A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) .. Then in a subsequent request, it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded.

      +

      Note: Versions mentioned in the description apply to the upstream krb5 package.

      +

      PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

      Remediation

      -

      Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.7 or higher.

      +

      There is no fixed version for Ubuntu:22.04 krb5.

      References


  • @@ -924,7 +903,7 @@

    CVE-2022-46908

  • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5, gnupg2/gpg@2.2.27-3ubuntu2.1 and others + docker-image|quay.io/argoproj/argocd@v2.5.6, gnupg2/gpg@2.2.27-3ubuntu2.1 and others
  • @@ -936,7 +915,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpg@2.2.27-3ubuntu2.1 @@ -993,7 +972,7 @@

      Uncontrolled Recursion

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and pcre3/libpcre3@2:8.39-13ubuntu0.22.04.1 + docker-image|quay.io/argoproj/argocd@v2.5.6 and pcre3/libpcre3@2:8.39-13ubuntu0.22.04.1
    @@ -1006,7 +985,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 pcre3/libpcre3@2:8.39-13ubuntu0.22.04.1 @@ -1015,7 +994,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 grep@3.7-1build1 @@ -1074,7 +1053,7 @@

      Release of Invalid Pointer or Reference

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and patch@2.7.6-7build2 + docker-image|quay.io/argoproj/argocd@v2.5.6 and patch@2.7.6-7build2
    @@ -1087,7 +1066,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 patch@2.7.6-7build2 @@ -1140,7 +1119,7 @@

      Double Free

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and patch@2.7.6-7build2 + docker-image|quay.io/argoproj/argocd@v2.5.6 and patch@2.7.6-7build2
    @@ -1153,7 +1132,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 patch@2.7.6-7build2 @@ -1211,7 +1190,7 @@

      Improper Locking

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and openssl/libssl3@3.0.2-0ubuntu1.7 + docker-image|quay.io/argoproj/argocd@v2.5.6 and openssl/libssl3@3.0.2-0ubuntu1.7
    @@ -1224,7 +1203,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 openssl/libssl3@3.0.2-0ubuntu1.7 @@ -1233,9 +1212,9 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 - cyrus-sasl2/libsasl2-modules@2.1.27+dfsg2-3ubuntu1 + cyrus-sasl2/libsasl2-modules@2.1.27+dfsg2-3ubuntu1.1 openssl/libssl3@3.0.2-0ubuntu1.7 @@ -1244,7 +1223,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 libfido2/libfido2-1@1.10.0-1 @@ -1255,7 +1234,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 openssh/openssh-client@1:8.9p1-3 @@ -1266,7 +1245,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ca-certificates@20211016ubuntu0.22.04.1 @@ -1279,11 +1258,11 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 libssh/libssh-4@0.9.6-2build1 @@ -1294,7 +1273,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 adduser@3.118ubuntu5 @@ -1317,7 +1296,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 openssl@3.0.2-0ubuntu1.7 @@ -1326,7 +1305,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ca-certificates@20211016ubuntu0.22.04.1 @@ -1382,7 +1361,7 @@

      CVE-2021-41617

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and openssh/openssh-client@1:8.9p1-3 + docker-image|quay.io/argoproj/argocd@v2.5.6 and openssh/openssh-client@1:8.9p1-3
    @@ -1395,7 +1374,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 openssh/openssh-client@1:8.9p1-3 @@ -1458,7 +1437,7 @@

      Information Exposure

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and openssh/openssh-client@1:8.9p1-3 + docker-image|quay.io/argoproj/argocd@v2.5.6 and openssh/openssh-client@1:8.9p1-3
    @@ -1471,7 +1450,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 openssh/openssh-client@1:8.9p1-3 @@ -1531,7 +1510,7 @@

      Out-of-bounds Read

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and ncurses/libtinfo6@6.3-2 + docker-image|quay.io/argoproj/argocd@v2.5.6 and ncurses/libtinfo6@6.3-2
    @@ -1544,7 +1523,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ncurses/libtinfo6@6.3-2 @@ -1553,7 +1532,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 bash@5.1-6ubuntu1 @@ -1564,7 +1543,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ncurses/libncursesw6@6.3-2 @@ -1575,7 +1554,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 less@590-1build1 @@ -1586,7 +1565,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 libedit/libedit2@3.1-20210910-1build1 @@ -1597,7 +1576,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ncurses/libncurses6@6.3-2 @@ -1608,7 +1587,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ncurses/ncurses-bin@6.3-2 @@ -1619,7 +1598,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 procps@2:3.3.17-6ubuntu2 @@ -1630,7 +1609,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 util-linux@2.37.2-4ubuntu3 @@ -1641,7 +1620,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpg@2.2.27-3ubuntu2.1 @@ -1656,7 +1635,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -1671,7 +1650,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ncurses/libncursesw6@6.3-2 @@ -1680,7 +1659,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 procps@2:3.3.17-6ubuntu2 @@ -1691,7 +1670,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -1706,7 +1685,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ncurses/libncurses6@6.3-2 @@ -1715,7 +1694,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 procps@2:3.3.17-6ubuntu2 @@ -1726,7 +1705,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ncurses/ncurses-base@6.3-2 @@ -1735,7 +1714,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 ncurses/ncurses-bin@6.3-2 @@ -1792,7 +1771,7 @@

      Integer Overflow or Wraparound

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and krb5/libk5crypto3@1.19.2-2 + docker-image|quay.io/argoproj/argocd@v2.5.6 and krb5/libk5crypto3@1.19.2-2
    @@ -1805,7 +1784,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 krb5/libk5crypto3@1.19.2-2 @@ -1814,7 +1793,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 adduser@3.118ubuntu5 @@ -1835,7 +1814,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 adduser@3.118ubuntu5 @@ -1858,7 +1837,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 krb5/libkrb5-3@1.19.2-2 @@ -1867,7 +1846,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 adduser@3.118ubuntu5 @@ -1888,7 +1867,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 krb5/libgssapi-krb5-2@1.19.2-2 @@ -1897,7 +1876,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 openssh/openssh-client@1:8.9p1-3 @@ -1908,11 +1887,11 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 krb5/libgssapi-krb5-2@1.19.2-2 @@ -1921,11 +1900,11 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 libssh/libssh-4@0.9.6-2build1 @@ -1936,7 +1915,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 adduser@3.118ubuntu5 @@ -1955,7 +1934,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 meta-common-packages@meta @@ -2013,7 +1992,7 @@

      CVE-2022-3219

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and gnupg2/gpgv@2.2.27-3ubuntu2.1 + docker-image|quay.io/argoproj/argocd@v2.5.6 and gnupg2/gpgv@2.2.27-3ubuntu2.1
    @@ -2026,7 +2005,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpgv@2.2.27-3ubuntu2.1 @@ -2035,7 +2014,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 apt@2.4.8 @@ -2046,7 +2025,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2057,7 +2036,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/dirmngr@2.2.27-3ubuntu2.1 @@ -2068,7 +2047,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpg@2.2.27-3ubuntu2.1 @@ -2079,7 +2058,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2092,7 +2071,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2105,7 +2084,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/dirmngr@2.2.27-3ubuntu2.1 @@ -2114,7 +2093,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2125,7 +2104,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2138,7 +2117,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg-l10n@2.2.27-3ubuntu2.1 @@ -2147,7 +2126,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2158,7 +2137,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg-utils@2.2.27-3ubuntu2.1 @@ -2167,7 +2146,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2178,7 +2157,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpg@2.2.27-3ubuntu2.1 @@ -2187,7 +2166,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2198,7 +2177,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2211,7 +2190,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2224,7 +2203,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpg-agent@2.2.27-3ubuntu2.1 @@ -2233,7 +2212,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2244,7 +2223,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2257,7 +2236,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2270,7 +2249,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpg-wks-client@2.2.27-3ubuntu2.1 @@ -2279,7 +2258,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2290,7 +2269,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpg-wks-server@2.2.27-3ubuntu2.1 @@ -2299,7 +2278,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2310,7 +2289,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gpgsm@2.2.27-3ubuntu2.1 @@ -2319,7 +2298,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2330,7 +2309,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2381,7 +2360,7 @@

      Allocation of Resources Without Limits or Throttling

      Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and glibc/libc-bin@2.35-0ubuntu3.1 + docker-image|quay.io/argoproj/argocd@v2.5.6 and glibc/libc-bin@2.35-0ubuntu3.1
    @@ -2394,7 +2373,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 glibc/libc-bin@2.35-0ubuntu3.1 @@ -2403,7 +2382,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 meta-common-packages@meta @@ -2461,7 +2440,7 @@

      Improper Input Validation

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5, git@1:2.34.1-1ubuntu1.5 and others + docker-image|quay.io/argoproj/argocd@v2.5.6, git@1:2.34.1-1ubuntu1.5 and others
    @@ -2473,7 +2452,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 git@1:2.34.1-1ubuntu1.5 @@ -2484,7 +2463,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 git@1:2.34.1-1ubuntu1.5 @@ -2493,7 +2472,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 git-lfs@3.0.2-1 @@ -2549,7 +2528,7 @@

      Improper Input Validation

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and coreutils@8.32-4.1ubuntu1 + docker-image|quay.io/argoproj/argocd@v2.5.6 and coreutils@8.32-4.1ubuntu1
    @@ -2562,7 +2541,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 coreutils@8.32-4.1ubuntu1 @@ -2597,7 +2576,7 @@

      References

    -

    Out-of-Bounds

    +

    Out-of-bounds Write

    @@ -2618,7 +2597,7 @@

    Out-of-Bounds

  • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 and bash@5.1-6ubuntu1 + docker-image|quay.io/argoproj/argocd@v2.5.6 and bash@5.1-6ubuntu1
  • @@ -2631,7 +2610,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.5.5 + docker-image|quay.io/argoproj/argocd@v2.5.6 bash@5.1-6ubuntu1 diff --git a/docs/snyk/v2.5.6/redis_7.0.7-alpine.html b/docs/snyk/v2.5.6/redis_7.0.7-alpine.html new file mode 100644 index 0000000000000..e0a3e7ad24fa8 --- /dev/null +++ b/docs/snyk/v2.5.6/redis_7.0.7-alpine.html @@ -0,0 +1,492 @@ + + + + + + + + + Snyk test report + + + + + + + + + +
      +
      +
      +
      + + + Snyk - Open Source Security + + + + + + + +
      +

      Snyk test report

      + +

      January 15th 2023, 12:21:21 am

      +
      +
      + Scanned the following path: +
        +
      • redis:7.0.7-alpine (apk)
      • +
      +
      + +
      +
      0 known vulnerabilities
      +
      0 vulnerable dependency paths
      +
      18 dependencies
      +
      +
      +
      +
      +
      +
    Project docker-image|quay.io/argoproj/argocd
    Path quay.io/argoproj/argocd:v2.5.5/argoproj/argocd
    Path quay.io/argoproj/argocd:v2.5.6/argoproj/argocd
    Package Manager deb
    Manifest Dockerfile
    + + + + + + +
    Project docker-image|redis
    Path redis:7.0.7-alpine
    Package Manager apk
    + +
    + No known vulnerabilities detected. +
    + + + + diff --git a/docs/snyk/v2.6.0-rc2/redis_7.0.5-alpine.html b/docs/snyk/v2.6.0-rc2/redis_7.0.5-alpine.html deleted file mode 100644 index a316b7d4faa40..0000000000000 --- a/docs/snyk/v2.6.0-rc2/redis_7.0.5-alpine.html +++ /dev/null @@ -1,646 +0,0 @@ - - - - - - - - - Snyk test report - - - - - - - - - -
    -
    -
    -
    - - - Snyk - Open Source Security - - - - - - - -
    -

    Snyk test report

    - -

    January 8th 2023, 12:18:25 am

    -
    -
    - Scanned the following path: -
      -
    • redis:7.0.5-alpine (apk)
    • -
    -
    - -
    -
    1 known vulnerabilities
    -
    9 vulnerable dependency paths
    -
    18 dependencies
    -
    -
    -
    -
    -
    - - - - - - - -
    Project docker-image|redis
    Path redis:7.0.5-alpine
    Package Manager apk
    -
    -
    -
    -
    -

    Improper Locking

    -
    - -
    - high severity -
    - -
    - -
      -
    • - Package Manager: alpine:3.17 -
    • -
    • - Vulnerable module: - - openssl/libcrypto3 -
    • - -
    • Introduced through: - - docker-image|redis@7.0.5-alpine and openssl/libcrypto3@3.0.7-r0 - -
    • -
    - -
    - - -

    Detailed paths

    - -
      -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libssl3@3.0.7-r0 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - .redis-rundeps@20221202.003022 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - apk-tools/apk-tools@2.12.10-r1 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - busybox/ssl_client@1.35.0-r29 - - openssl/libcrypto3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - .redis-rundeps@20221202.003022 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - apk-tools/apk-tools@2.12.10-r1 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    • - Introduced through: - docker-image|redis@7.0.5-alpine - - busybox/ssl_client@1.35.0-r29 - - openssl/libssl3@3.0.7-r0 - - - -
    • -
    - -
    - -
    - -

    NVD Description

    -

    Note: Versions mentioned in the description apply to the upstream openssl package. - See How to fix? for Alpine:3.17 relevant versions.

    -

    If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the -policy&#39; argument to the command line utilities or by calling either X509_VERIFY_PARAM_add0_policy()' or `X509_VERIFY_PARAM_set1_policies()' functions.

    -

    Remediation

    -

    Upgrade Alpine:3.17 openssl to version 3.0.7-r2 or higher.

    -

    References

    - - -
    - - - -
    -
    -
    -
    - - - diff --git a/docs/snyk/v2.6.0-rc2/argocd-iac-install.html b/docs/snyk/v2.6.0-rc3/argocd-iac-install.html similarity index 98% rename from docs/snyk/v2.6.0-rc2/argocd-iac-install.html rename to docs/snyk/v2.6.0-rc3/argocd-iac-install.html index 2850bf97220c0..91ece7f30e166 100644 --- a/docs/snyk/v2.6.0-rc2/argocd-iac-install.html +++ b/docs/snyk/v2.6.0-rc3/argocd-iac-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:20:07 am

    +

    January 15th 2023, 12:20:17 am

    Scanned the following path: @@ -507,7 +507,7 @@

    Role with dangerous permissions

  • - Line number: 15180 + Line number: 15177
  • @@ -553,7 +553,7 @@

    Role with dangerous permissions

  • - Line number: 15257 + Line number: 15254
  • @@ -599,7 +599,7 @@

    Role with dangerous permissions

  • - Line number: 15285 + Line number: 15282
  • @@ -645,7 +645,7 @@

    Role with dangerous permissions

  • - Line number: 15329 + Line number: 15326
  • @@ -691,7 +691,7 @@

    Role with dangerous permissions

  • - Line number: 15311 + Line number: 15308
  • @@ -737,7 +737,7 @@

    Role with dangerous permissions

  • - Line number: 15345 + Line number: 15342
  • @@ -789,7 +789,7 @@

    Container could be running with outdated image

  • - Line number: 16349 + Line number: 16346
  • @@ -847,7 +847,7 @@

    Container has no CPU limit

  • - Line number: 15812 + Line number: 15809
  • @@ -905,7 +905,7 @@

    Container has no CPU limit

  • - Line number: 15985 + Line number: 15982
  • @@ -963,7 +963,7 @@

    Container has no CPU limit

  • - Line number: 15951 + Line number: 15948
  • @@ -1021,7 +1021,7 @@

    Container has no CPU limit

  • - Line number: 16041 + Line number: 16038
  • @@ -1079,7 +1079,7 @@

    Container has no CPU limit

  • - Line number: 16115 + Line number: 16112
  • @@ -1137,7 +1137,7 @@

    Container has no CPU limit

  • - Line number: 16349 + Line number: 16346
  • @@ -1195,7 +1195,7 @@

    Container has no CPU limit

  • - Line number: 16171 + Line number: 16168
  • @@ -1253,7 +1253,7 @@

    Container has no CPU limit

  • - Line number: 16434 + Line number: 16431
  • @@ -1311,7 +1311,7 @@

    Container has no CPU limit

  • - Line number: 16738 + Line number: 16735
  • @@ -1363,7 +1363,7 @@

    Container is running with multiple open ports

  • - Line number: 15965 + Line number: 15962
  • @@ -1419,7 +1419,7 @@

    Container is running with writable root filesystem

  • - Line number: 16125 + Line number: 16122
  • @@ -1471,7 +1471,7 @@

    Container is running without liveness probe

  • - Line number: 15812 + Line number: 15809
  • @@ -1523,7 +1523,7 @@

    Container is running without liveness probe

  • - Line number: 15951 + Line number: 15948
  • @@ -1575,7 +1575,7 @@

    Container is running without liveness probe

  • - Line number: 15985 + Line number: 15982
  • @@ -1627,7 +1627,7 @@

    Container is running without liveness probe

  • - Line number: 16115 + Line number: 16112
  • @@ -1679,7 +1679,7 @@

    Container is running without liveness probe

  • - Line number: 16349 + Line number: 16346
  • @@ -1737,7 +1737,7 @@

    Container is running without memory limit

  • - Line number: 15812 + Line number: 15809
  • @@ -1795,7 +1795,7 @@

    Container is running without memory limit

  • - Line number: 15951 + Line number: 15948
  • @@ -1853,7 +1853,7 @@

    Container is running without memory limit

  • - Line number: 15985 + Line number: 15982
  • @@ -1911,7 +1911,7 @@

    Container is running without memory limit

  • - Line number: 16041 + Line number: 16038
  • @@ -1969,7 +1969,7 @@

    Container is running without memory limit

  • - Line number: 16115 + Line number: 16112
  • @@ -2027,7 +2027,7 @@

    Container is running without memory limit

  • - Line number: 16349 + Line number: 16346
  • @@ -2085,7 +2085,7 @@

    Container is running without memory limit

  • - Line number: 16171 + Line number: 16168
  • @@ -2143,7 +2143,7 @@

    Container is running without memory limit

  • - Line number: 16434 + Line number: 16431
  • @@ -2201,7 +2201,7 @@

    Container is running without memory limit

  • - Line number: 16738 + Line number: 16735
  • diff --git a/docs/snyk/v2.6.0-rc2/argocd-iac-namespace-install.html b/docs/snyk/v2.6.0-rc3/argocd-iac-namespace-install.html similarity index 99% rename from docs/snyk/v2.6.0-rc2/argocd-iac-namespace-install.html rename to docs/snyk/v2.6.0-rc3/argocd-iac-namespace-install.html index 0dd0196d18e2d..655555eaca9ef 100644 --- a/docs/snyk/v2.6.0-rc2/argocd-iac-namespace-install.html +++ b/docs/snyk/v2.6.0-rc3/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:20:18 am

    +

    January 15th 2023, 12:20:27 am

    Scanned the following path: diff --git a/docs/snyk/v2.6.0-rc2/argocd-test.html b/docs/snyk/v2.6.0-rc3/argocd-test.html similarity index 96% rename from docs/snyk/v2.6.0-rc2/argocd-test.html rename to docs/snyk/v2.6.0-rc3/argocd-test.html index 63b738e039850..a11cf14169973 100644 --- a/docs/snyk/v2.6.0-rc2/argocd-test.html +++ b/docs/snyk/v2.6.0-rc3/argocd-test.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:17:50 am

    +

    January 15th 2023, 12:18:12 am

    Scanned the following paths: @@ -466,9 +466,9 @@

    Snyk test report

    -
    2 known vulnerabilities
    -
    117 vulnerable dependency paths
    -
    1731 dependencies
    +
    1 known vulnerabilities
    +
    116 vulnerable dependency paths
    +
    1730 dependencies
    @@ -476,90 +476,6 @@

    Snyk test report

    -
    -

    Prototype Poisoning

    -
    - -
    - high severity -
    - -
    - -
      -
    • - Package Manager: npm -
    • -
    • - Vulnerable module: - - qs -
    • - -
    • Introduced through: - - - argo-cd-ui@1.0.0, superagent@7.1.6 and others -
    • -
    - -
    - - -

    Detailed paths

    - -
      -
    • - Introduced through: - argo-cd-ui@1.0.0 - - superagent@7.1.6 - - formidable@2.0.1 - - qs@6.9.3 - - - -
    • -
    - -
    - -
    - -

    Overview

    -

    qs is a querystring parser that supports nesting and arrays, with a depth limit.

    -

    Affected versions of this package are vulnerable to Prototype Poisoning which allows attackers to cause a Node process to hang, processing an Array object whose prototype has been replaced by one with an excessive length value.

    -

    Note: In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000.

    -

    Details

    -

    Denial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its intended and legitimate users.

    -

    Unlike other vulnerabilities, DoS attacks usually do not aim at breaching security. Rather, they are focused on making websites and services unavailable to genuine users resulting in downtime.

    -

    One popular Denial of Service vulnerability is DDoS (a Distributed Denial of Service), an attack that attempts to clog network pipes to the system by generating a large volume of traffic from many machines.

    -

    When it comes to open source libraries, DoS vulnerabilities allow attackers to trigger such a crash or crippling of the service by using a flaw either in the application code or from the use of open source libraries.

    -

    Two common types of DoS vulnerabilities:

    -
      -
    • High CPU/Memory Consumption- An attacker sending crafted requests that could cause the system to take a disproportionate amount of time to process. For example, commons-fileupload:commons-fileupload.

      -
    • -
    • Crash - An attacker sending crafted requests that could cause the system to crash. For Example, npm ws package

      -
    • -
    -

    Remediation

    -

    Upgrade qs to version 6.2.4, 6.3.3, 6.4.1, 6.5.3, 6.6.1, 6.7.3, 6.8.3, 6.9.7, 6.10.3 or higher.

    -

    References

    - - -
    - - - -

    Denial of Service (DoS)

    diff --git a/docs/snyk/v2.5.5/ghcr.io_dexidp_dex_v2.35.3.html b/docs/snyk/v2.6.0-rc3/ghcr.io_dexidp_dex_v2.35.3.html similarity index 99% rename from docs/snyk/v2.5.5/ghcr.io_dexidp_dex_v2.35.3.html rename to docs/snyk/v2.6.0-rc3/ghcr.io_dexidp_dex_v2.35.3.html index 20cb2817f62a9..9b7aedaf9fc53 100644 --- a/docs/snyk/v2.5.5/ghcr.io_dexidp_dex_v2.35.3.html +++ b/docs/snyk/v2.6.0-rc3/ghcr.io_dexidp_dex_v2.35.3.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:20:45 am

    +

    January 15th 2023, 12:18:19 am

    Scanned the following path: diff --git a/docs/snyk/v2.6.0-rc2/haproxy_2.6.2-alpine.html b/docs/snyk/v2.6.0-rc3/haproxy_2.6.2-alpine.html similarity index 99% rename from docs/snyk/v2.6.0-rc2/haproxy_2.6.2-alpine.html rename to docs/snyk/v2.6.0-rc3/haproxy_2.6.2-alpine.html index 201b3042805e8..b18b87f7f7595 100644 --- a/docs/snyk/v2.6.0-rc2/haproxy_2.6.2-alpine.html +++ b/docs/snyk/v2.6.0-rc3/haproxy_2.6.2-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    January 8th 2023, 12:17:58 am

    +

    January 15th 2023, 12:18:21 am

    Scanned the following path: diff --git a/docs/snyk/v2.6.0-rc2/quay.io_argoproj_argocd_v2.6.0-rc2.html b/docs/snyk/v2.6.0-rc3/quay.io_argoproj_argocd_v2.6.0-rc3.html similarity index 89% rename from docs/snyk/v2.6.0-rc2/quay.io_argoproj_argocd_v2.6.0-rc2.html rename to docs/snyk/v2.6.0-rc3/quay.io_argoproj_argocd_v2.6.0-rc3.html index b3023beb4bca4..5d398efe1fc31 100644 --- a/docs/snyk/v2.6.0-rc2/quay.io_argoproj_argocd_v2.6.0-rc2.html +++ b/docs/snyk/v2.6.0-rc3/quay.io_argoproj_argocd_v2.6.0-rc3.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,18 +456,18 @@

    Snyk test report

    -

    January 8th 2023, 12:18:20 am

    +

    January 15th 2023, 12:18:43 am

    Scanned the following path:
      -
    • quay.io/argoproj/argocd:v2.6.0-rc2/argoproj/argocd (deb)
    • +
    • quay.io/argoproj/argocd:v2.6.0-rc3/argoproj/argocd (deb)
    -
    17 known vulnerabilities
    -
    93 vulnerable dependency paths
    +
    16 known vulnerabilities
    +
    102 vulnerable dependency paths
    162 dependencies
    @@ -477,7 +477,7 @@

    Snyk test report

    - + @@ -507,7 +507,7 @@

    Off-by-one Error

  • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and systemd/libsystemd0@249.11-0ubuntu3.6 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and systemd/libsystemd0@249.11-0ubuntu3.6
  • @@ -520,7 +520,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 systemd/libsystemd0@249.11-0ubuntu3.6 @@ -529,7 +529,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 apt@2.4.8 @@ -540,7 +540,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 procps/libprocps8@2:3.3.17-6ubuntu2 @@ -551,7 +551,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 util-linux@2.37.2-4ubuntu3 @@ -562,7 +562,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 util-linux/bsdutils@1:2.37.2-4ubuntu3 @@ -573,7 +573,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 apt@2.4.8 @@ -586,7 +586,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 systemd/libudev1@249.11-0ubuntu3.6 @@ -595,7 +595,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 libfido2/libfido2-1@1.10.0-1 @@ -606,7 +606,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 util-linux@2.37.2-4ubuntu3 @@ -617,7 +617,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 apt@2.4.8 @@ -657,7 +657,7 @@

      References

      -

      CVE-2022-43552

      +

      Integer Overflow or Wraparound

      @@ -673,13 +673,13 @@

      CVE-2022-43552

    • Vulnerable module: - curl/libcurl3-gnutls + krb5/libk5crypto3
    • Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and krb5/libk5crypto3@1.19.2-2 - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2, git@1:2.34.1-1ubuntu1.5 and others
    @@ -691,77 +691,161 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 - - git@1:2.34.1-1ubuntu1.5 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + krb5/libk5crypto3@1.19.2-2
    • -
    - - - -
    - -

    NVD Description

    -

    This vulnerability has not been analyzed by NVD yet.

    -

    Remediation

    -

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.7 or higher.

    -

    References

    - - -
    - - - - -
    -

    Cleartext Transmission of Sensitive Information

    -
    - -
    - medium severity -
    - -
    +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2 + + -
      -
    • - Package Manager: ubuntu:22.04 -
    • -
    • - Vulnerable module: +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + krb5/libk5crypto3@1.19.2-2 + + - curl/libcurl3-gnutls -
    • + +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + krb5/libkrb5-3@1.19.2-2 + + -
    • Introduced through: +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + krb5/libkrb5-3@1.19.2-2 + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + krb5/libgssapi-krb5-2@1.19.2-2 + + - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2, git@1:2.34.1-1ubuntu1.5 and others -
    • -
    +
  • +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + openssh/openssh-client@1:8.9p1-3ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + -
    +
  • +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 + + krb5/libgssapi-krb5-2@1.19.2-2 + + +
  • +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 + + libssh/libssh-4@0.9.6-2build1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + -

    Detailed paths

    +
  • +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 + + adduser@3.118ubuntu5 + + shadow/passwd@1:4.8.1-2ubuntu2.1 + + pam/libpam-modules@1.4.0-11ubuntu2 + + libnsl/libnsl2@1.3.0-2build2 + + libtirpc/libtirpc3@1.3.2-2ubuntu0.1 + + krb5/libgssapi-krb5-2@1.19.2-2 + + -
      +
    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 - git@1:2.34.1-1ubuntu1.5 + meta-common-packages@meta - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + krb5/libkrb5support0@1.19.2-2 @@ -773,23 +857,26 @@

      Detailed paths


      NVD Description

      -

      Note: Versions mentioned in the description apply to the upstream curl package. - See How to fix? for Ubuntu:22.04 relevant versions.

      -

      A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) .. Then in a subsequent request, it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded.

      +

      Note: Versions mentioned in the description apply to the upstream krb5 package.

      +

      PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

      Remediation

      -

      Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.7 or higher.

      +

      There is no fixed version for Ubuntu:22.04 krb5.

      References


  • @@ -816,7 +903,7 @@

    CVE-2022-46908

  • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2, gnupg2/gpg@2.2.27-3ubuntu2.1 and others + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3, gnupg2/gpg@2.2.27-3ubuntu2.1 and others
  • @@ -828,7 +915,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpg@2.2.27-3ubuntu2.1 @@ -885,7 +972,7 @@

      Uncontrolled Recursion

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and pcre3/libpcre3@2:8.39-13ubuntu0.22.04.1 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and pcre3/libpcre3@2:8.39-13ubuntu0.22.04.1
    @@ -898,7 +985,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 pcre3/libpcre3@2:8.39-13ubuntu0.22.04.1 @@ -907,7 +994,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 grep@3.7-1build1 @@ -966,7 +1053,7 @@

      Release of Invalid Pointer or Reference

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and patch@2.7.6-7build2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and patch@2.7.6-7build2
    @@ -979,7 +1066,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 patch@2.7.6-7build2 @@ -1032,7 +1119,7 @@

      Double Free

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and patch@2.7.6-7build2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and patch@2.7.6-7build2
    @@ -1045,7 +1132,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 patch@2.7.6-7build2 @@ -1103,7 +1190,7 @@

      Improper Locking

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and openssl/libssl3@3.0.2-0ubuntu1.7 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and openssl/libssl3@3.0.2-0ubuntu1.7
    @@ -1116,7 +1203,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 openssl/libssl3@3.0.2-0ubuntu1.7 @@ -1125,7 +1212,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 cyrus-sasl2/libsasl2-modules@2.1.27+dfsg2-3ubuntu1.1 @@ -1136,7 +1223,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 libfido2/libfido2-1@1.10.0-1 @@ -1147,9 +1234,9 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 - openssh/openssh-client@1:8.9p1-3 + openssh/openssh-client@1:8.9p1-3ubuntu0.1 openssl/libssl3@3.0.2-0ubuntu1.7 @@ -1158,7 +1245,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ca-certificates@20211016ubuntu0.22.04.1 @@ -1171,11 +1258,11 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 libssh/libssh-4@0.9.6-2build1 @@ -1186,7 +1273,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 adduser@3.118ubuntu5 @@ -1209,7 +1296,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 openssl@3.0.2-0ubuntu1.7 @@ -1218,7 +1305,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ca-certificates@20211016ubuntu0.22.04.1 @@ -1274,7 +1361,7 @@

      CVE-2021-41617

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and openssh/openssh-client@1:8.9p1-3 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and openssh/openssh-client@1:8.9p1-3ubuntu0.1
    @@ -1287,9 +1374,9 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 - openssh/openssh-client@1:8.9p1-3 + openssh/openssh-client@1:8.9p1-3ubuntu0.1 @@ -1350,7 +1437,7 @@

      Information Exposure

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and openssh/openssh-client@1:8.9p1-3 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and openssh/openssh-client@1:8.9p1-3ubuntu0.1
    @@ -1363,9 +1450,9 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 - openssh/openssh-client@1:8.9p1-3 + openssh/openssh-client@1:8.9p1-3ubuntu0.1 @@ -1423,7 +1510,7 @@

      Out-of-bounds Read

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and ncurses/libtinfo6@6.3-2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and ncurses/libtinfo6@6.3-2
    @@ -1436,7 +1523,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ncurses/libtinfo6@6.3-2 @@ -1445,7 +1532,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 bash@5.1-6ubuntu1 @@ -1456,7 +1543,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ncurses/libncursesw6@6.3-2 @@ -1467,7 +1554,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 less@590-1build1 @@ -1478,7 +1565,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 libedit/libedit2@3.1-20210910-1build1 @@ -1489,7 +1576,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ncurses/libncurses6@6.3-2 @@ -1500,7 +1587,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ncurses/ncurses-bin@6.3-2 @@ -1511,7 +1598,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 procps@2:3.3.17-6ubuntu2 @@ -1522,7 +1609,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 util-linux@2.37.2-4ubuntu3 @@ -1533,7 +1620,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpg@2.2.27-3ubuntu2.1 @@ -1548,7 +1635,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -1563,7 +1650,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ncurses/libncursesw6@6.3-2 @@ -1572,7 +1659,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 procps@2:3.3.17-6ubuntu2 @@ -1583,7 +1670,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -1598,7 +1685,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ncurses/libncurses6@6.3-2 @@ -1607,7 +1694,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 procps@2:3.3.17-6ubuntu2 @@ -1618,7 +1705,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ncurses/ncurses-base@6.3-2 @@ -1627,7 +1714,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 ncurses/ncurses-bin@6.3-2 @@ -1684,7 +1771,7 @@

      Integer Overflow or Wraparound

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and krb5/libk5crypto3@1.19.2-2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and krb5/libk5crypto3@1.19.2-2
    @@ -1697,7 +1784,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 krb5/libk5crypto3@1.19.2-2 @@ -1706,7 +1793,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 adduser@3.118ubuntu5 @@ -1727,7 +1814,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 adduser@3.118ubuntu5 @@ -1750,7 +1837,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 krb5/libkrb5-3@1.19.2-2 @@ -1759,7 +1846,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 adduser@3.118ubuntu5 @@ -1780,7 +1867,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 krb5/libgssapi-krb5-2@1.19.2-2 @@ -1789,9 +1876,9 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 - openssh/openssh-client@1:8.9p1-3 + openssh/openssh-client@1:8.9p1-3ubuntu0.1 krb5/libgssapi-krb5-2@1.19.2-2 @@ -1800,11 +1887,11 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 krb5/libgssapi-krb5-2@1.19.2-2 @@ -1813,11 +1900,11 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.7 libssh/libssh-4@0.9.6-2build1 @@ -1828,7 +1915,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 adduser@3.118ubuntu5 @@ -1847,7 +1934,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 meta-common-packages@meta @@ -1905,7 +1992,7 @@

      CVE-2022-3219

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and gnupg2/gpgv@2.2.27-3ubuntu2.1 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and gnupg2/gpgv@2.2.27-3ubuntu2.1
    @@ -1918,7 +2005,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpgv@2.2.27-3ubuntu2.1 @@ -1927,7 +2014,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 apt@2.4.8 @@ -1938,7 +2025,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -1949,7 +2036,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/dirmngr@2.2.27-3ubuntu2.1 @@ -1960,7 +2047,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpg@2.2.27-3ubuntu2.1 @@ -1971,7 +2058,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -1984,7 +2071,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -1997,7 +2084,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/dirmngr@2.2.27-3ubuntu2.1 @@ -2006,7 +2093,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2017,7 +2104,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2030,7 +2117,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg-l10n@2.2.27-3ubuntu2.1 @@ -2039,7 +2126,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2050,7 +2137,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg-utils@2.2.27-3ubuntu2.1 @@ -2059,7 +2146,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2070,7 +2157,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpg@2.2.27-3ubuntu2.1 @@ -2079,7 +2166,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2090,7 +2177,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2103,7 +2190,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2116,7 +2203,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpg-agent@2.2.27-3ubuntu2.1 @@ -2125,7 +2212,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2136,7 +2223,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2149,7 +2236,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2162,7 +2249,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpg-wks-client@2.2.27-3ubuntu2.1 @@ -2171,7 +2258,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2182,7 +2269,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpg-wks-server@2.2.27-3ubuntu2.1 @@ -2191,7 +2278,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2202,7 +2289,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gpgsm@2.2.27-3ubuntu2.1 @@ -2211,7 +2298,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2222,7 +2309,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 gnupg2/gnupg@2.2.27-3ubuntu2.1 @@ -2273,7 +2360,7 @@

      Allocation of Resources Without Limits or Throttling

      Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and glibc/libc-bin@2.35-0ubuntu3.1 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and glibc/libc-bin@2.35-0ubuntu3.1
    @@ -2286,7 +2373,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 glibc/libc-bin@2.35-0ubuntu3.1 @@ -2295,7 +2382,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 meta-common-packages@meta @@ -2353,7 +2440,7 @@

      Improper Input Validation

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2, git@1:2.34.1-1ubuntu1.5 and others + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3, git@1:2.34.1-1ubuntu1.5 and others
    @@ -2365,7 +2452,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 git@1:2.34.1-1ubuntu1.5 @@ -2376,7 +2463,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 git@1:2.34.1-1ubuntu1.5 @@ -2385,7 +2472,7 @@

      Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 git-lfs@3.0.2-1 @@ -2441,7 +2528,7 @@

      Improper Input Validation

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and coreutils@8.32-4.1ubuntu1 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and coreutils@8.32-4.1ubuntu1
    @@ -2454,7 +2541,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 coreutils@8.32-4.1ubuntu1 @@ -2489,7 +2576,7 @@

      References

    -

    Out-of-Bounds

    +

    Out-of-bounds Write

    @@ -2510,7 +2597,7 @@

    Out-of-Bounds

  • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 and bash@5.1-6ubuntu1 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 and bash@5.1-6ubuntu1
  • @@ -2523,7 +2610,7 @@

    Detailed paths

    • Introduced through: - docker-image|quay.io/argoproj/argocd@v2.6.0-rc2 + docker-image|quay.io/argoproj/argocd@v2.6.0-rc3 bash@5.1-6ubuntu1 diff --git a/docs/snyk/v2.6.0-rc3/redis_7.0.7-alpine.html b/docs/snyk/v2.6.0-rc3/redis_7.0.7-alpine.html new file mode 100644 index 0000000000000..6d35cfcc878cd --- /dev/null +++ b/docs/snyk/v2.6.0-rc3/redis_7.0.7-alpine.html @@ -0,0 +1,492 @@ + + + + + + + + + Snyk test report + + + + + + + + + +
      +
      +
      +
      + + + Snyk - Open Source Security + + + + + + + +
      +

      Snyk test report

      + +

      January 15th 2023, 12:18:46 am

      +
      +
      + Scanned the following path: +
        +
      • redis:7.0.7-alpine (apk)
      • +
      +
      + +
      +
      0 known vulnerabilities
      +
      0 vulnerable dependency paths
      +
      18 dependencies
      +
      +
      +
      +
      +
      +
    Project docker-image|quay.io/argoproj/argocd
    Path quay.io/argoproj/argocd:v2.6.0-rc2/argoproj/argocd
    Path quay.io/argoproj/argocd:v2.6.0-rc3/argoproj/argocd
    Package Manager deb
    Manifest Dockerfile
    + + + + + + +
    Project docker-image|redis
    Path redis:7.0.7-alpine
    Package Manager apk
    + +
    + No known vulnerabilities detected. +
    + + + +