atomist-skills / owasp-dependency-check-skill

Other
0 stars 0 forks source link

Vulnerability update in gcr.io/atomist-container-skills/owasp-dependency-check-skill (unstable) #135

Closed atomist[bot] closed 2 years ago

atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
CVE-2021-42740critical9.8shell-quote 1.7.242
Details Commit 5ebed053fe3cb367aa6890996ad183771a7fb129
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 5ebed053fe3cb367aa6890996ad183771a7fb129
Digest sha256:6b016dbf07f461164d5d44296a420194415011cb873bfe113613be66a8ef72ed
Scanned October 31, 2021, 12:01 AM UTC
unstable set October 7, 2021, 6:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
CVE-2021-28831high7.5busybox 1.31.1-r20 > 1.32.1-r4x13
Details Commit 5ebed053fe3cb367aa6890996ad183771a7fb129
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 5ebed053fe3cb367aa6890996ad183771a7fb129
Digest sha256:6b016dbf07f461164d5d44296a420194415011cb873bfe113613be66a8ef72ed
Scanned November 14, 2021, 12:03 AM UTC
unstable set October 7, 2021, 6:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

Vulnerability updates
CVESeverityCVSSPackagesFixLine
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
CVE-2021-42386severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42385severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42384severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42383severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42382severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42381severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42380severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42379severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42378severity_unspecified > highn/a > 7.2busybox 1.31.1-r20 > 1.31.1-r21x13
Details Commit 5ebed053fe3cb367aa6890996ad183771a7fb129
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 5ebed053fe3cb367aa6890996ad183771a7fb129
Digest sha256:6b016dbf07f461164d5d44296a420194415011cb873bfe113613be66a8ef72ed
Scanned November 18, 2021, 12:05 AM UTC
unstable set October 7, 2021, 6:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

Vulnerability updates
CVESeverityCVSSPackagesFixLine
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
CVE-2021-42374severity_unspecified > criticaln/a > 9.1busybox 1.31.1-r20 > 1.31.1-r21x13
CVE-2021-42375severity_unspecified > highn/a > 7.5busybox 1.31.1-r20 > 1.31.1-r21x13
Details Commit 5ebed053fe3cb367aa6890996ad183771a7fb129
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 5ebed053fe3cb367aa6890996ad183771a7fb129
Digest sha256:6b016dbf07f461164d5d44296a420194415011cb873bfe113613be66a8ef72ed
Scanned November 19, 2021, 12:10 AM UTC
unstable set October 7, 2021, 6:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Details Commit 5ebed053fe3cb367aa6890996ad183771a7fb129
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 5ebed053fe3cb367aa6890996ad183771a7fb129
Digest sha256:6b016dbf07f461164d5d44296a420194415011cb873bfe113613be66a8ef72ed
Scanned November 26, 2021, 12:45 AM UTC
unstable set October 7, 2021, 6:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2021-3918critical9.8json-schema 0.2.3 > 0.4.0x2
Details Commit 5ebed053fe3cb367aa6890996ad183771a7fb129
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 5ebed053fe3cb367aa6890996ad183771a7fb129
Digest sha256:6b016dbf07f461164d5d44296a420194415011cb873bfe113613be66a8ef72ed
Scanned December 1, 2021, 1:10 AM UTC
unstable set October 7, 2021, 6:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2021-39537high8.8ncurses 6.2_p20200523-r0 > 6.2_p20200523-r1x2
Details Commit 5ebed053fe3cb367aa6890996ad183771a7fb129
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 5ebed053fe3cb367aa6890996ad183771a7fb129
Digest sha256:6b016dbf07f461164d5d44296a420194415011cb873bfe113613be66a8ef72ed
Scanned December 10, 2021, 1:55 AM UTC
unstable set October 7, 2021, 6:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2021-43809medium > high6.7 > 7.3bundler 2.2.26 > 2.2.33x2
Details Commit 5ebed053fe3cb367aa6890996ad183771a7fb129
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 5ebed053fe3cb367aa6890996ad183771a7fb129
Digest sha256:6b016dbf07f461164d5d44296a420194415011cb873bfe113613be66a8ef72ed
Scanned December 15, 2021, 2:25 AM UTC
unstable set October 7, 2021, 6:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2021-23463critical9.1h2 1.4.1992
Details Commit c8851b2315d51df01d28c232e919925dfda71e1c
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag c8851b2315d51df01d28c232e919925dfda71e1c
Digest sha256:a9feac355df335c096d0ce9b7bd2d39f97e474b7be3bfa283b0e17bcaefd09f2
Scanned December 16, 2021, 2:20 PM UTC
unstable set December 15, 2021, 2:18 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
GHSA-h376-j262-vhq6criticaln/ah2 1.4.199 > 2.0.206x2
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned January 7, 2022, 11:00 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerabilities
CVESeverityCVSSPackagesFixLine
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
GHSA-wrvw-hg22-4m67highn/aprotobuf-java 3.11.4 > 3.16.1x47
CVE-2021-22569highn/aprotobuf-java 3.11.4 > 3.19.2, 3.18.2, 3.16.1x47
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned January 8, 2022, 11:04 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2021-42392criticaln/ah2 1.4.199 > 2.0.206x2
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned January 13, 2022, 3:10 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerabilities
CVESeverityCVSSPackagesFixLine
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned January 17, 2022, 3:25 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerabilities
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2022-22824critical9.8expat 2.4.1-r0 > 2.4.3-r0x2
CVE-2022-22823critical9.8expat 2.4.1-r0 > 2.4.3-r0x2
CVE-2022-22822critical9.8expat 2.4.1-r0 > 2.4.3-r0x2
CVE-2022-22827high8.8expat 2.4.1-r0 > 2.4.3-r0x2
CVE-2022-22826high8.8expat 2.4.1-r0 > 2.4.3-r0x2
CVE-2022-22825high8.8expat 2.4.1-r0 > 2.4.3-r0x2
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned January 18, 2022, 3:30 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerabilities
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2022-23221criticaln/ah2 1.4.199 > 2.1.210x2
CVE-2021-41819high7.5cgi 0.1.0.1 > 0.3.1x2
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned January 22, 2022, 3:55 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerabilities
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2022-23990critical9.8expat 2.4.1-r0 > 2.4.4-r0x2
CVE-2022-23852critical9.8expat 2.4.1-r0 > 2.4.4-r0x2
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
CVE-2021-22570high7.5protobuf-java 3.11.447
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned February 4, 2022, 6:45 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerability
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2022-21724highn/apostgresql 42.2.19 > 42.3.2, 42.2.25x2
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned February 5, 2022, 6:50 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2022-21724high > criticaln/a > 9.8postgresql 42.2.19 > 42.3.2, 42.2.25x2
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned February 8, 2022, 7:11 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

New vulnerabilities
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2021-44533highn/anodejs 14.18.1-r0 > 14.19.0-r0x2
CVE-2021-44532highn/anodejs 14.18.1-r0 > 14.19.0-r0x2
CVE-2021-44531highn/anodejs 14.18.1-r0 > 14.19.0-r0x2
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned February 10, 2022, 11:30 AM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/owasp-dependency-check-skill set as unstable:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image owasp/dependency-check:latest
CVE-2021-41816severity_unspecified > criticaln/a > 9.8cgi 0.1.0.1 > 0.1.1x2
Details Commit 70a208e9662833a35a6e192c67f99e7f363b8059
Image gcr.io/atomist-container-skills/owasp-dependency-check-skill
Tag 70a208e9662833a35a6e192c67f99e7f363b8059
Digest sha256:960f1ba5dd894d8f8fc0eab460b76f134e1b987bcd16187a5d427fa33b57d624
Scanned February 16, 2022, 12:21 PM UTC
unstable set January 3, 2022, 10:41 PM UTC
atomist[bot] commented 2 years ago

Thanks for your contribution!

This issue has been automatically marked with stale because it has not had any activity in last 50 days. It will be closed in 7 days if no further activity occurs. To prevent closing, label with defer or blocked or any of the changelog: labels.