CVE shows as High vulnerability but REDHAT says not affected?
@cdupuis ci sta già lavorando.
Dal 28/7/2023.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
We are running RedHat 8
The package python3-urllib3-1.24.2-5.el8.noarch is installed.
Scout is showing 3 vulnerabilities for this package:
=============
0C 1H 2M 0L urllib3 1.24.2
pkg:pypi/[email protected]
✗ HIGH CVE-2021-33503
https://scout.docker.com/v/CVE-2021-33503
Affected range : <1.26.5
Fixed version : 1.26.5
✗ MEDIUM CVE-2020-26137 [Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')]
https://scout.docker.com/v/CVE-2020-26137
Affected range : <1.25.9
Fixed version : 1.25.9
CVSS Score : 6.5
CVSS Vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
✗ MEDIUM CVE-2019-11236 [Improper Neutralization of CRLF Sequences ('CRLF Injection')]
https://scout.docker.com/v/CVE-2019-11236
Affected range : <=1.24.2
Fixed version : 1.24.3
CVSS Score : 6.1
CVSS Vector : CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
=================
For the first one -- https://scout.docker.com/v/CVE-2021-33503 Redhat website says the first is Not Affected
For the 2nd one https://access.redhat.com/security/cve/CVE-2020-26137
Redhat says it is addressed in the version we have installed: https://access.redhat.com/errata/RHSA-2021:1631
( if you click on updated packages it shows python-urllib3-1.24.2-5.el8.src.rpm as being updted.
For the 3rd one https://scout.docker.com/vulnerabilities/id/CVE-2019-11236
It says < <1.24.2-2.el8 is vulnerable -- we have python3-urllib3-1.24.2-5.el8.noarch which is greater -- and is the patched version.
Not sure why these are showing as vulnerabilities when we have patched version from redhat.
Could be something to do with the "version" shown in scout finding only has the point release and not the - redhat modified version that contains the backport of the fixes.
e.g SCOUT thinks we have pkg:pypi/[email protected] but we have 1.24.2-5
- Lingua principale
- Shell
- Stelle
- 455
- Fork
- 134
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di docker/scout-cli
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
GO-2026-5932: golang.org/x/crypto reported vulnerable at module level, ignoring import scopingAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
-
allstar
Difficoltà 2/5 1-3 ore Idoneità per principianti 45/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar existsAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 64/100
Tutte le issue di docker/scout-cli
Issue simili
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
alunduil/alunduil-infrastructure#629 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
duckdb/duckdb-skills#19 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
YosysHQ/oss-cad-suite-build#216 ·