CVE shows as High vulnerability but REDHAT says not affected?
@cdupuis đang làm issue này rồi.
Từ ngày 28/7/2023.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
We are running RedHat 8
The package python3-urllib3-1.24.2-5.el8.noarch is installed.
Scout is showing 3 vulnerabilities for this package:
=============
0C 1H 2M 0L urllib3 1.24.2
pkg:pypi/[email protected]
✗ HIGH CVE-2021-33503
https://scout.docker.com/v/CVE-2021-33503
Affected range : <1.26.5
Fixed version : 1.26.5
✗ MEDIUM CVE-2020-26137 [Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')]
https://scout.docker.com/v/CVE-2020-26137
Affected range : <1.25.9
Fixed version : 1.25.9
CVSS Score : 6.5
CVSS Vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
✗ MEDIUM CVE-2019-11236 [Improper Neutralization of CRLF Sequences ('CRLF Injection')]
https://scout.docker.com/v/CVE-2019-11236
Affected range : <=1.24.2
Fixed version : 1.24.3
CVSS Score : 6.1
CVSS Vector : CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
=================
For the first one -- https://scout.docker.com/v/CVE-2021-33503 Redhat website says the first is Not Affected
For the 2nd one https://access.redhat.com/security/cve/CVE-2020-26137
Redhat says it is addressed in the version we have installed: https://access.redhat.com/errata/RHSA-2021:1631
( if you click on updated packages it shows python-urllib3-1.24.2-5.el8.src.rpm as being updted.
For the 3rd one https://scout.docker.com/vulnerabilities/id/CVE-2019-11236
It says < <1.24.2-2.el8 is vulnerable -- we have python3-urllib3-1.24.2-5.el8.noarch which is greater -- and is the patched version.
Not sure why these are showing as vulnerabilities when we have patched version from redhat.
Could be something to do with the "version" shown in scout finding only has the point release and not the - redhat modified version that contains the backport of the fixes.
e.g SCOUT thinks we have pkg:pypi/[email protected] but we have 1.24.2-5
- Ngôn ngữ chính
- Shell
- Star
- 455
- Fork
- 134
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của docker/scout-cli
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
GO-2026-5932: golang.org/x/crypto reported vulnerable at module level, ignoring import scopingĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
-
allstar
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 45/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar existsĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 64/100
Tất cả issue của docker/scout-cli
Issue tương tự
-
bot-found bug priority: P3
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
madenvel/KalinkaPlayer#179 ·
-
[platform-assessment 2026-09]Đang mởdocumentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
jbaruch/coding-policy#621 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
mattpocock/skills#1134 ·
-
area:build bug P3
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
uttrflow/uttrflow-swift#2506 ·
Maintainer thường phản hồi trong vòng 1 ngày