Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

tools(connector-fabric): address CVEs: CVE-2022-21190, CVE-2021-3918 #2864

Closed
zondervancalvez opened this issue Nov 6, 2023 · 5 comments · Fixed by #2967 or #3324
Closed

tools(connector-fabric): address CVEs: CVE-2022-21190, CVE-2021-3918 #2864

zondervancalvez opened this issue Nov 6, 2023 · 5 comments · Fixed by #2967 or #3324
Assignees

Comments

@zondervancalvez
Copy link
Contributor

Description

Vulnerabilities were found during the container scan of connector-fabric image using Trivy.
See the list below:

LIBRARY VULNERABILITY INSTALLED VERSION FIXED VERSION
libsasl2-2
libsasl2-modules
libsasl2-modules-db
CVE-2022-24407 2.1.27+dfsg-2 2.1.27+dfsg-2ubuntu0.1
libssl1.1 CVE-2021-3711
CVE-2022-0778
CVE-2023-0286
1.1.1f-1ubuntu2.5 1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.17
openssl CVE-2021-3711
CVE-2022-0778
CVE-2023-0286
  1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.17
@npmcli/arborist (package.json) CVE-2021-39134
CVE-2021-39135
2.6.4 2.8.2
ansi-regex (package.json) CVE-2021-3807 3.0.0, 5.0.0 6.0.1, 5.0.1, 4.1.1, 3.0.1
axios (package.json) CVE-2021-3749 0.21.1 0.21.2
convict (package.json) CVE-2022-21190
CVE-2022-22143
CVE-2023-0163
6.0.0 6.2.3
6.2.3
6.2.4
engine.io (package.json) CVE-2022-21676 5.0.0 4.1.2, 5.2.1, 6.1.1
http-cache-semantics (package.json) CVE-2022-25881 4.1.0 4.1.1
json-schema (package.json) CVE-2021-3918 0.2.3 0.4.0
minimatch (package.json) CVE-2022-3517 3.0.4 3.0.5
node-forge (package.json) CVE-2022-24771
CVE-2022-24772
0.10.0 1.3.0
npm (package.json) CVE-2022-29244 7.19.1 8.11.0
qs (package.json) CVE-2022-24999 6.5.2, 6.7.0 6.10.3, 6.9.7, 6.8.3,
6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, 6.2.4
socket.io-parser (package.json) CVE-2023-32695 4.0.5 4.2.3, 3.4.3
tar (package.json) CVE-2021-32803
CVE-2021-32804
CVE-2021-37701
CVE-2021-37712
CVE-2021-37713
6.1.0 3.2.3, 4.4.15, 5.0.7, 6.1.2
3.2.2, 4.4.14, 5.0.6, 6.1.1
4.4.16, 5.0.8, 6.1.7
4.4.18, 5.0.10, 6.1.9
@petermetz
Copy link
Contributor

@zondervancalvez Could you please make the issue title unique according to the guidelines we talked about previously?

@zondervancalvez zondervancalvez changed the title fix(security): vulnerabilities found in connector-fabric tools(connector-fabric): address CVEs: CVE-2022-24407, CVE-2021-3711, CVE-2022-0778, CVE-2023-0286, CVE-2021-3711, CVE-2022-0778, CVE-2023-0286, CVE-2021-39134, CVE-2021-39135, CVE-2021-3807, CVE-2021-3749, CVE-2022-21190, CVE-2022-22143, CVE-2023-0163, CVE-2022-21676, CVE-2022-25881, CVE-2021-3918 CVE-2022-3517, CVE-2022-24771, CVE-2022-24772, CVE-2022-29244, CVE-2022-24999, CVE-2023-32695, CVE-2021-32803, CVE-2021-32804, CVE-2021-37701, CVE-2021-37712, CVE-2021-37713 Nov 7, 2023
@petermetz
Copy link
Contributor

@zondervancalvez Please shorten it to adhere to the commit lint max length requirements. What I do in these situations is pick the top (most severe) 1 or 2 or 3 CVE IDs (depending on how many characters do you have left) and use only those.

@zondervancalvez zondervancalvez changed the title tools(connector-fabric): address CVEs: CVE-2022-24407, CVE-2021-3711, CVE-2022-0778, CVE-2023-0286, CVE-2021-3711, CVE-2022-0778, CVE-2023-0286, CVE-2021-39134, CVE-2021-39135, CVE-2021-3807, CVE-2021-3749, CVE-2022-21190, CVE-2022-22143, CVE-2023-0163, CVE-2022-21676, CVE-2022-25881, CVE-2021-3918 CVE-2022-3517, CVE-2022-24771, CVE-2022-24772, CVE-2022-29244, CVE-2022-24999, CVE-2023-32695, CVE-2021-32803, CVE-2021-32804, CVE-2021-37701, CVE-2021-37712, CVE-2021-37713 tools(connector-fabric): address CVEs: CVE-2022-21190, CVE-2021-3918 Nov 8, 2023
@zondervancalvez
Copy link
Contributor Author

@zondervancalvez Please shorten it to adhere to the commit lint max length requirements. What I do in these situations is pick the top (most severe) 1 or 2 or 3 CVE IDs (depending on how many characters do you have left) and use only those.

Hi @petermetz The title is now shortened and I've only indicated the Critical CVEs.

@petermetz
Copy link
Contributor

@zondervancalvez Please shorten it to adhere to the commit lint max length requirements. What I do in these situations is pick the top (most severe) 1 or 2 or 3 CVE IDs (depending on how many characters do you have left) and use only those.

Hi @petermetz The title is now shortened and I've only indicated the Critical CVEs.

@zondervancalvez Thank you very much!

zondervancalvez referenced this issue in zondervancalvez/cactus Nov 10, 2023
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Nov 10, 2023
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Nov 14, 2023
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
@adrianbatuto
Copy link
Contributor

Can you assign this to me? @jagpreetsinghsasan

adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Jan 3, 2024
@adrianbatuto adrianbatuto moved this from In Progress to In review in Cacti_Scrum_Project_v2_Release Jan 11, 2024
zondervancalvez referenced this issue in zondervancalvez/cactus Jan 16, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Jan 23, 2024
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Jan 23, 2024
petermetz pushed a commit to adrianbatuto/cacti that referenced this issue Jan 25, 2024
petermetz pushed a commit that referenced this issue Jan 25, 2024
@github-project-automation github-project-automation bot moved this from In review to Done in Cacti_Scrum_Project_v2_Release Jan 25, 2024
zondervancalvez referenced this issue in zondervancalvez/cactus Feb 13, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Feb 28, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Feb 28, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Feb 28, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Mar 18, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Mar 18, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Mar 18, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Mar 19, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Mar 25, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Apr 1, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Apr 3, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Apr 4, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus Apr 4, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
zondervancalvez referenced this issue in zondervancalvez/cactus May 21, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
petermetz referenced this issue May 21, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
sandeepnRES referenced this issue in sandeepnRES/cacti Jul 30, 2024
Trivy is a cutting-edge security tool designed to enhance
the safety of containerized applications by conducting thorough
vulnerability assessments. Specifically developed for scanning
container images, ranging from low-severity issues to critical
threats. It employs an intelligent rating system to categorize
vulnerabilities based on their severity levels, ensuring that
high to critical vulnerabilities are given special attention.
Upon detecting vulnerabilities that fall within this elevated
range, Trivy will throw an error.

By integrating Trivy into our deployment pipeline, we can
proactively mitigate security risks and enhance the resilience
of our repository.

Fixes hyperledger#1876

Depends On: hyperledger#2865
Depends On: hyperledger#2864
Depends On: hyperledger#2863
Depends On: hyperledger#2862

Signed-off-by: zondervancalvez <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
3 participants