LukKoko / Test

Test
0 stars 0 forks source link

Fix vulnerability warning #61

Open ghost opened 2 years ago

ghost commented 2 years ago

Pipelines throw warning during deployments:

Vulnerable Packages Found

DSA-5085-2 Policy Status: Active

Summary: The update for expat released as DSA 5085-1 introduced regressions for applications using URI characters (':' in particular) for a namespace separator (while the HTML API docs of function XML_ParserCreateNS have been advising against their use). Updated expat packages are now available which relax the fix for CVE-2022-25236 with regard to RFC 3986 URI characters.

Vendor Security Notice IDs Official Notice
DSA-5085-2 https://lists.debian.org/debian-security-announce/2022/msg00069.html

Affected Packages Policy Status How to Resolve Security Notice
libexpat1 Active Upgrade libexpat1 to >= 2.2.10-2+deb11u3 DSA-5085-2

ghost commented 2 years ago

e.g.: https://cloud.ibm.com/devops/pipelines/9d2df10d-dd5a-474a-af28-cf733641432d/c15917f1-1ff2-4e6a-a31b-227fd27b5017/7cdf46ad-2152-4327-866f-4f61290b5fcf?env_id=ibm:yp:eu-de