CVE shows as High vulnerability but REDHAT says not affected?
@cdupuis がすでに取り組んでいます。
2023年7月28日 から。
評価
この issue はまだ評価されていません。
説明
We are running RedHat 8
The package python3-urllib3-1.24.2-5.el8.noarch is installed.
Scout is showing 3 vulnerabilities for this package:
=============
0C 1H 2M 0L urllib3 1.24.2
pkg:pypi/[email protected]
✗ HIGH CVE-2021-33503
https://scout.docker.com/v/CVE-2021-33503
Affected range : <1.26.5
Fixed version : 1.26.5
✗ MEDIUM CVE-2020-26137 [Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')]
https://scout.docker.com/v/CVE-2020-26137
Affected range : <1.25.9
Fixed version : 1.25.9
CVSS Score : 6.5
CVSS Vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
✗ MEDIUM CVE-2019-11236 [Improper Neutralization of CRLF Sequences ('CRLF Injection')]
https://scout.docker.com/v/CVE-2019-11236
Affected range : <=1.24.2
Fixed version : 1.24.3
CVSS Score : 6.1
CVSS Vector : CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
=================
For the first one -- https://scout.docker.com/v/CVE-2021-33503 Redhat website says the first is Not Affected
For the 2nd one https://access.redhat.com/security/cve/CVE-2020-26137
Redhat says it is addressed in the version we have installed: https://access.redhat.com/errata/RHSA-2021:1631
( if you click on updated packages it shows python-urllib3-1.24.2-5.el8.src.rpm as being updted.
For the 3rd one https://scout.docker.com/vulnerabilities/id/CVE-2019-11236
It says < <1.24.2-2.el8 is vulnerable -- we have python3-urllib3-1.24.2-5.el8.noarch which is greater -- and is the patched version.
Not sure why these are showing as vulnerabilities when we have patched version from redhat.
Could be something to do with the "version" shown in scout finding only has the point release and not the - redhat modified version that contains the backport of the fixes.
e.g SCOUT thinks we have pkg:pypi/[email protected] but we have 1.24.2-5
- 主要言語
- Shell
- スター
- 455
- フォーク
- 134
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
docker/scout-cli のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
-
allstar
難易度 2/5 1〜3時間 初心者へのやさしさ 45/100
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar existsオープン
難易度 4/5 3〜5日 初心者へのやさしさ 64/100
docker/scout-cli の issue をすべて見る
似ている issue
-
bot-found bug priority: P3
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
madenvel/KalinkaPlayer#179 ·
-
documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
jbaruch/coding-policy#621 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
mattpocock/skills#1134 ·
-
area:build bug P3
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
uttrflow/uttrflow-swift#2506 ·
メンテナーはふだん 1 日以内に返信