GitHub
02/03/2023, 7:11 AMx):
☑︎ Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project.
☑︎ Upgraded to the latest Pact Broker Docker image OR
☑︎ Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed
☑︎ Read the Troubleshooting page
Software versions
• pact-broker docker version: 2.89.1.0
Expected behaviour
no high Vulnerability issue
Actual behaviour
4 high Vulnerability issues
Steps to reproduce
twistlock scan
Relevent log files
1. Private keys stored in image
2. An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.", "severity": "high", "packageName": "ncurses", "packageVersion": "6.2_p20210109-r0", "link": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-39537"
3. In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.", "severity": "high", "packageName": "rdoc", "packageVersion": "6.1.2.1", "link": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-31799"
4. The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.", "severity": "high", "packageName": "underscore", "packageVersion": "1.4.4", "link": "https://github.com/advisories",
Please ensure you set logging to DEBUG and attach any relevant log files here (or link from a gist).
pact-foundation/pact-broker-dockerGitHub
02/03/2023, 7:11 AM