Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Numerous LOW vulnerabilities/CVEs reported to CIS Version : 2.18.1 #3689

Open
F5JC opened this issue Dec 16, 2024 · 1 comment
Open

Numerous LOW vulnerabilities/CVEs reported to CIS Version : 2.18.1 #3689

F5JC opened this issue Dec 16, 2024 · 1 comment

Comments

@F5JC
Copy link

F5JC commented Dec 16, 2024

Setup Details

CIS Version : 2.18.1
Build: f5networks/k8s-bigip-ctlr:latest

Description

VA tool reports numerous LOW vulnerabilities.

Steps To Reproduce

Expected Result

Actual Result

"CVE-2019-12900, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2019-12900"
"CVE-2024-7264, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-7264"
"CVE-2024-9681, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-9681"
"CVE-2023-4156, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2023-4156"
"CVE-2023-32636, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2023-32636"
"CVE-2022-3219, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2022-3219"
"CVE-2024-26458, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9331"
"CVE-2024-26461, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9331"
"CVE-2024-7264, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-7264"
"CVE-2024-9681, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-9681"
"CVE-2022-27943, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2022-27943"
"CVE-2022-27943, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2022-27943"
"CVE-2023-45322, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2023-45322"
"CVE-2024-34459, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-34459"
"CVE-2022-4899, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2022-4899"
"CVE-2022-29458, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2022-29458"
"CVE-2023-50495, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2023-50495"
"CVE-2022-29458, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2022-29458"
"CVE-2023-50495, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2023-50495"
"CVE-2023-2953, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2023-2953"
"CVE-2024-2511, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9333"
"CVE-2024-41996, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-41996"
"CVE-2024-4603, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9333"
"CVE-2024-4741, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9333"
"CVE-2024-5535, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9333"
"CVE-2024-2511, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9333"
"CVE-2024-41996, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-41996"
"CVE-2024-4603, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9333"
"CVE-2024-4741, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9333"
"CVE-2024-5535, Severity: LOW, Source: https://access.redhat.com/errata/RHSA-2024:9333"
"CVE-2022-41409, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2022-41409"
"CVE-2022-41409, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2022-41409"
"CVE-2024-0397, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-0397"
"CVE-2024-7592, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-7592"
"CVE-2024-0397, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-0397"
"CVE-2024-7592, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-7592"
"CVE-2024-0397, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-0397"
"CVE-2024-7592, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-7592"
"CVE-2021-3572, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2021-3572"
"CVE-2024-0232, Severity: LOW, Source: https://access.redhat.com/security/cve/CVE-2024-0232"

Diagnostic Information

Observations (if any)

VA tool policy: "Evaluated policies: Global-Image-Secret-Scan, Global-Image-SensitiveData-Scan, Global-Image-Vulnerability-Scan"

@F5JC F5JC added bug untriaged no JIRA created labels Dec 16, 2024
@trinaths
Copy link
Contributor

Created [CONTCNTR-5136] for internal tracking.

@trinaths trinaths added JIRA and removed untriaged no JIRA created labels Jan 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants