CVE shows as High vulnerability but REDHAT says not affected?
@cdupuis is already working on this.
Since Jul 28, 2023.
Assessment
This issue has not been assessed yet.
Description
We are running RedHat 8
The package python3-urllib3-1.24.2-5.el8.noarch is installed.
Scout is showing 3 vulnerabilities for this package:
=============
0C 1H 2M 0L urllib3 1.24.2
pkg:pypi/[email protected]
✗ HIGH CVE-2021-33503
https://scout.docker.com/v/CVE-2021-33503
Affected range : <1.26.5
Fixed version : 1.26.5
✗ MEDIUM CVE-2020-26137 [Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')]
https://scout.docker.com/v/CVE-2020-26137
Affected range : <1.25.9
Fixed version : 1.25.9
CVSS Score : 6.5
CVSS Vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
✗ MEDIUM CVE-2019-11236 [Improper Neutralization of CRLF Sequences ('CRLF Injection')]
https://scout.docker.com/v/CVE-2019-11236
Affected range : <=1.24.2
Fixed version : 1.24.3
CVSS Score : 6.1
CVSS Vector : CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
=================
For the first one -- https://scout.docker.com/v/CVE-2021-33503 Redhat website says the first is Not Affected
For the 2nd one https://access.redhat.com/security/cve/CVE-2020-26137
Redhat says it is addressed in the version we have installed: https://access.redhat.com/errata/RHSA-2021:1631
( if you click on updated packages it shows python-urllib3-1.24.2-5.el8.src.rpm as being updted.
For the 3rd one https://scout.docker.com/vulnerabilities/id/CVE-2019-11236
It says < <1.24.2-2.el8 is vulnerable -- we have python3-urllib3-1.24.2-5.el8.noarch which is greater -- and is the patched version.
Not sure why these are showing as vulnerabilities when we have patched version from redhat.
Could be something to do with the "version" shown in scout finding only has the point release and not the - redhat modified version that contains the backport of the fixes.
e.g SCOUT thinks we have pkg:pypi/[email protected] but we have 1.24.2-5
- Dominant language
- Shell
- Stars
- 455
- Forks
- 134
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from docker/scout-cli
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
allstar
Difficulty 2/5 1-3 hours Newbie friendliness 45/100
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar existsOpen
Difficulty 4/5 3-5 days Newbie friendliness 64/100
All issues in docker/scout-cli
Similar issues
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
alunduil/alunduil-infrastructure#629 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
duckdb/duckdb-skills#19 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
YosysHQ/oss-cad-suite-build#216 ·