<#71 twist lock security issue> Issue created by <...
# pact-broker
g
#71 twist lock security issue Issue created by linl2 Pre issue-raising checklist I have already (please mark the applicable with an
x
): ☑︎ Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project. ☑︎ Upgraded to the latest Pact Broker Docker image OR ☑︎ Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed ☑︎ Read the Troubleshooting page Software versions • pact-broker docker version: 2.89.1.0 Expected behaviour no high Vulnerability issue Actual behaviour 4 high Vulnerability issues Steps to reproduce twistlock scan Relevent log files 1. Private keys stored in image 2. An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.", "severity": "high", "packageName": "ncurses", "packageVersion": "6.2_p20210109-r0", "link": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-39537" 3. In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.", "severity": "high", "packageName": "rdoc", "packageVersion": "6.1.2.1", "link": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-31799" 4. The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.", "severity": "high", "packageName": "underscore", "packageVersion": "1.4.4", "link": "https://github.com/advisories", Please ensure you set logging to
DEBUG
and attach any relevant log files here (or link from a gist). pact-foundation/pact-broker-docker