teerth04 / ticket

Other
0 stars 0 forks source link

Findings for Container Security, Low, [TheRedHatter/javagoof:Dockerfile]:Missing Initialization of Resource #1808

Open armorcodegithubpreprod[bot] opened 4 months ago

armorcodegithubpreprod[bot] commented 4 months ago

Findings for Container Security, Low, [TheRedHatter/javagoof:Dockerfile]:Missing Initialization of Resource

Component Details

curl 7.7 through 7.76.1 suffers from an information disclosure when the -t command line option, known as CURLOPT_TELNETOPTIONS in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

References

Origin : null Type : null Image Id : null

Snyk Project Status: Active



armorcodegithubpreprod[bot] commented 4 months ago

Finding [47833204|https://preprod.armorcode.ai/#/findings/257/1167/47833204] is Mitigated
by SYSTEM via ArmorCode Platform

armorcodegithubpreprod[bot] commented 4 months ago

Finding [47833204|https://preprod.armorcode.ai/#/findings/257/1167/47833204] status changed to Confirmed Note:
by SYSTEM via ArmorCode Platform