Please take care of the Vulnerabilities in image jimmidyson/configmap-reload:v0.7.1
[1mScan results for: image jimmidyson/configmap-reload:v0.7.1 sha256:db09e1c4a336e6a36a43b8910f8cc474a36ee05a5237ac296362df43bc246df7[0m
[1mVulnerabilities[0m
+----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+
| [1m CVE [0m | [1mSEVERITY[0m | [1mCVSS[0m | [1mPACKAGE[0m | [1mVERSION[0m | [1m STATUS [0m | [1mPUBLISHED[0m | [1mDISCOVERED[0m | [1m DESCRIPTION [0m |
+----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+
| [0mCVE-2022-23806[0m | [31;1mcritical[0m | [0m9.10[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 1.17.7, 1.16.14[0m | [0m49 days[0m | [0m< 1 hour[0m | [0mCurve.IsOnCurve in crypto/elliptic in Go before[0m |
| | | | | | 49 days ago | | | 1.16.14 and 1.17.x before 1.17.7 can incorrectly |
| | | | | | | | | return true in situations with a big.Int value |
| | | | | | | | | that i... |
+----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+
| [0mCVE-2022-27191[0m | [91;1mhigh[0m | [0m7.50[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 0.0.0[0m | [0m14 days[0m | [0m< 1 hour[0m | [0mgolang.org/x/crypto/ssh before[0m |
| | | | | | 14 days ago | | | 0.0.0-20220314234659-1baeb1ce4c0b in Go through |
| | | | | | | | | 1.16.15 and 1.17.x through 1.17.8 allows an |
| | | | | | | | | attacker to crash a server ... |
+----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+
| [0mCVE-2022-24921[0m | [91;1mhigh[0m | [0m7.50[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 1.17.8, 1.16.15[0m | [0m27 days[0m | [0m< 1 hour[0m | [0mregexp.Compile in Go before 1.16.15 and 1.17.x[0m |
| | | | | | 27 days ago | | | before 1.17.8 allows stack exhaustion via a deeply |
| | | | | | | | | nested expression. |
+----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+
| [0mCVE-2022-23773[0m | [91;1mhigh[0m | [0m7.50[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 1.17.7, 1.16.14[0m | [0m49 days[0m | [0m< 1 hour[0m | [0mcmd/go in Go before 1.16.14 and 1.17.x before[0m |
| | | | | | 49 days ago | | | 1.17.7 can misinterpret branch names that falsely |
| | | | | | | | | appear to be version tags. This can lead to |
| | | | | | | | | incorrect ... |
+----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+
| [0mCVE-2022-23772[0m | [91;1mhigh[0m | [0m7.50[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 1.17.7, 1.16.14[0m | [0m49 days[0m | [0m< 1 hour[0m | [0mRat.SetString in math/big in Go before 1.16.14 and[0m |
| | | | | | 49 days ago | | | 1.17.x before 1.17.7 has an overflow that can lead |
| | | | | | | | | to Uncontrolled Memory Consumption. |
+----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+
[1mVulnerabilities found for image jimmidyson/configmap-reload:v0.7.1: total - 5, critical - 1, high - 4, medium - 0, low - 0[0m
[1mVulnerability threshold check results: PASS[0m
[1mCompliance found for image jimmidyson/configmap-reload:v0.7.1: total - 0, critical - 0, high - 0, medium - 0, low - 0[0m
[1mCompliance threshold check results: PASS[0m
Thanks for reporting! I have rebuilt and republished the v0.7.1 images so I'm going to close this. If you rescan and still find vulnerabilities, please reopen this issue.
Please take care of the Vulnerabilities in image jimmidyson/configmap-reload:v0.7.1 [1mScan results for: image jimmidyson/configmap-reload:v0.7.1 sha256:db09e1c4a336e6a36a43b8910f8cc474a36ee05a5237ac296362df43bc246df7[0m [1mVulnerabilities[0m +----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+ | [1m CVE [0m | [1mSEVERITY[0m | [1mCVSS[0m | [1mPACKAGE[0m | [1mVERSION[0m | [1m STATUS [0m | [1mPUBLISHED[0m | [1mDISCOVERED[0m | [1m DESCRIPTION [0m | +----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+ | [0mCVE-2022-23806[0m | [31;1mcritical[0m | [0m9.10[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 1.17.7, 1.16.14[0m | [0m49 days[0m | [0m< 1 hour[0m | [0mCurve.IsOnCurve in crypto/elliptic in Go before[0m | | | | | | | 49 days ago | | | 1.16.14 and 1.17.x before 1.17.7 can incorrectly | | | | | | | | | | return true in situations with a big.Int value | | | | | | | | | | that i... | +----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+ | [0mCVE-2022-27191[0m | [91;1mhigh[0m | [0m7.50[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 0.0.0[0m | [0m14 days[0m | [0m< 1 hour[0m | [0mgolang.org/x/crypto/ssh before[0m | | | | | | | 14 days ago | | | 0.0.0-20220314234659-1baeb1ce4c0b in Go through | | | | | | | | | | 1.16.15 and 1.17.x through 1.17.8 allows an | | | | | | | | | | attacker to crash a server ... | +----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+ | [0mCVE-2022-24921[0m | [91;1mhigh[0m | [0m7.50[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 1.17.8, 1.16.15[0m | [0m27 days[0m | [0m< 1 hour[0m | [0mregexp.Compile in Go before 1.16.15 and 1.17.x[0m | | | | | | | 27 days ago | | | before 1.17.8 allows stack exhaustion via a deeply | | | | | | | | | | nested expression. | +----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+ | [0mCVE-2022-23773[0m | [91;1mhigh[0m | [0m7.50[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 1.17.7, 1.16.14[0m | [0m49 days[0m | [0m< 1 hour[0m | [0mcmd/go in Go before 1.16.14 and 1.17.x before[0m | | | | | | | 49 days ago | | | 1.17.7 can misinterpret branch names that falsely | | | | | | | | | | appear to be version tags. This can lead to | | | | | | | | | | incorrect ... | +----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+ | [0mCVE-2022-23772[0m | [91;1mhigh[0m | [0m7.50[0m | [0mgo[0m | [0m1.17.6[0m | [0mfixed in 1.17.7, 1.16.14[0m | [0m49 days[0m | [0m< 1 hour[0m | [0mRat.SetString in math/big in Go before 1.16.14 and[0m | | | | | | | 49 days ago | | | 1.17.x before 1.17.7 has an overflow that can lead | | | | | | | | | | to Uncontrolled Memory Consumption. | +----------------+----------+------+---------+---------+--------------------------+-----------+------------+----------------------------------------------------+
[1mVulnerabilities found for image jimmidyson/configmap-reload:v0.7.1: total - 5, critical - 1, high - 4, medium - 0, low - 0[0m [1mVulnerability threshold check results: PASS[0m
[1mCompliance found for image jimmidyson/configmap-reload:v0.7.1: total - 0, critical - 0, high - 0, medium - 0, low - 0[0m [1mCompliance threshold check results: PASS[0m