interlynk-io / sbomqs

SBOM quality score - Quality metrics for your sboms
Apache License 2.0
158 stars 20 forks source link

Vulnerability found On scanning sbomqs image: v0.1.7 #298

Open viveksahu26 opened 1 month ago

viveksahu26 commented 1 month ago


Image scanning

I ran Trivy to scan the image and found multiple vulnerabilities. Below are the details of the scan:

$  trivy image

2024-07-22T22:14:55+05:30   INFO    Vulnerability scanning is enabled
2024-07-22T22:14:55+05:30   INFO    Secret scanning is enabled
2024-07-22T22:14:55+05:30   INFO    If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-07-22T22:14:55+05:30   INFO    Please see also for faster secret detection
2024-07-22T22:15:00+05:30   INFO    Number of language-specific files   num=1
2024-07-22T22:15:00+05:30   INFO    [gobinary] Detecting vulnerabilities...
2024-07-22T22:15:00+05:30   WARN    Using severities from other vendors for some vulnerabilities. Read for details.

app/sbomqs (gobinary)

Total: 4 (UNKNOWN: 0, LOW: 0, MEDIUM: 2, HIGH: 1, CRITICAL: 1)

│ Library │ Vulnerability  │ Severity │ Status │ Installed Version │  Fixed Version  │                            Title                             │
│ stdlib  │ CVE-2024-24790 │ CRITICAL │ fixed  │ 1.22.2            │ 1.21.11, 1.22.4 │ golang: net/netip: Unexpected behavior from Is methods for   │
│         │                │          │        │                   │                 │ IPv4-mapped IPv6 addresses                                   │
│         │                │          │        │                   │                 │                   │
│         ├────────────────┼──────────┤        │                   ├─────────────────┼──────────────────────────────────────────────────────────────┤
│         │ CVE-2024-24788 │ HIGH     │        │                   │ 1.22.3          │ golang: net: malformed DNS message can cause infinite loop   │
│         │                │          │        │                   │                 │                   │
│         ├────────────────┼──────────┤        │                   ├─────────────────┼──────────────────────────────────────────────────────────────┤
│         │ CVE-2024-24789 │ MEDIUM   │        │                   │ 1.21.11, 1.22.4 │ golang: archive/zip: Incorrect handling of certain ZIP files │
│         │                │          │        │                   │                 │                   │
│         ├────────────────┤          │        │                   ├─────────────────┼──────────────────────────────────────────────────────────────┤
│         │ CVE-2024-24791 │          │        │                   │ 1.21.12, 1.22.5 │ net/http: Denial of service due to improper 100-continue     │
│         │                │          │        │                   │                 │ handling in net/http                                         │
│         │                │          │        │                   │                 │                   │

Repository scanning

Whereas on repository scanning didn't found as such vulnerabilities.

$ trivy repository   

2024-07-22T22:21:27+05:30   INFO    Vulnerability scanning is enabled
2024-07-22T22:21:27+05:30   INFO    Secret scanning is enabled
2024-07-22T22:21:27+05:30   INFO    If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-07-22T22:21:27+05:30   INFO    Please see also for faster secret detection
Enumerating objects: 743, done.
Counting objects: 100% (743/743), done.
Compressing objects: 100% (442/442), done.
Total 743 (delta 489), reused 480 (delta 283), pack-reused 0
2024-07-22T22:21:30+05:30   INFO    Number of language-specific files   num=1
2024-07-22T22:21:30+05:30   INFO    [gomod] Detecting vulnerabilities...


We should patch up this vulnerabilities.