From a765c141ca41b98423a8c5f827dfb7a286bebd95 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Mon, 31 Oct 2022 10:21:03 -0400 Subject: [PATCH] [Bot] Update Snyk reports (#11114) Signed-off-by: CI Signed-off-by: CI Co-authored-by: CI --- docs/snyk/index.md | 10 +- docs/snyk/master/argocd-iac-install.html | 2 +- .../master/argocd-iac-namespace-install.html | 2 +- docs/snyk/master/argocd-test.html | 2 +- ...ghcr.io_dexidp_dex_v2.35.3-distroless.html | 2 +- docs/snyk/master/haproxy_2.6.2-alpine.html | 2 +- .../quay.io_argoproj_argocd_latest.html | 98 +++++- docs/snyk/master/redis_7.0.5-alpine.html | 2 +- docs/snyk/v2.2.15/argocd-iac-install.html | 2 +- .../v2.2.15/argocd-iac-namespace-install.html | 2 +- docs/snyk/v2.2.15/argocd-test.html | 2 +- ...ghcr.io_dexidp_dex_v2.35.3-distroless.html | 2 +- docs/snyk/v2.2.15/haproxy_2.0.29-alpine.html | 2 +- .../quay.io_argoproj_argocd_v2.2.15.html | 320 +++++++++++++++++- docs/snyk/v2.2.15/redis_6.2.7-alpine.html | 2 +- docs/snyk/v2.3.10/argocd-iac-install.html | 2 +- .../v2.3.10/argocd-iac-namespace-install.html | 2 +- docs/snyk/v2.3.10/argocd-test.html | 2 +- ...ghcr.io_dexidp_dex_v2.35.3-distroless.html | 2 +- docs/snyk/v2.3.10/haproxy_2.0.29-alpine.html | 2 +- ...argoproj_argocd-applicationset_v0.4.1.html | 23 +- .../quay.io_argoproj_argocd_v2.3.10.html | 296 +++++++++++++++- docs/snyk/v2.3.10/redis_6.2.7-alpine.html | 2 +- docs/snyk/v2.4.15/argocd-iac-install.html | 2 +- .../v2.4.15/argocd-iac-namespace-install.html | 2 +- docs/snyk/v2.4.15/argocd-test.html | 2 +- ...ghcr.io_dexidp_dex_v2.35.3-distroless.html | 2 +- docs/snyk/v2.4.15/haproxy_2.0.29-alpine.html | 2 +- .../quay.io_argoproj_argocd_v2.4.15.html | 296 +++++++++++++++- docs/snyk/v2.4.15/redis_7.0.4-alpine.html | 2 +- docs/snyk/v2.5.0-rc3/argocd-iac-install.html | 2 +- .../argocd-iac-namespace-install.html | 2 +- docs/snyk/v2.5.0-rc3/argocd-test.html | 2 +- ...ghcr.io_dexidp_dex_v2.35.3-distroless.html | 2 +- .../snyk/v2.5.0-rc3/haproxy_2.6.2-alpine.html | 2 +- .../quay.io_argoproj_argocd_v2.5.0-rc3.html | 302 ++++++++++++++++- docs/snyk/v2.5.0-rc3/redis_7.0.5-alpine.html | 2 +- 37 files changed, 1312 insertions(+), 93 deletions(-) diff --git a/docs/snyk/index.md b/docs/snyk/index.md index 0a58ffd4151d5..b8af331a9868b 100644 --- a/docs/snyk/index.md +++ b/docs/snyk/index.md @@ -17,7 +17,7 @@ recent minor releases. | [ui/yarn.lock](master/argocd-test.html) | 0 | 0 | 3 | 0 | | [dex:v2.35.3-distroless](master/ghcr.io_dexidp_dex_v2.35.3-distroless.html) | 0 | 0 | 0 | 0 | | [haproxy:2.6.2-alpine](master/haproxy_2.6.2-alpine.html) | 0 | 0 | 0 | 0 | -| [argocd:latest](master/quay.io_argoproj_argocd_latest.html) | 0 | 0 | 0 | 13 | +| [argocd:latest](master/quay.io_argoproj_argocd_latest.html) | 0 | 0 | 1 | 13 | | [redis:7.0.5-alpine](master/redis_7.0.5-alpine.html) | 0 | 0 | 0 | 0 | | [install.yaml](master/argocd-iac-install.html) | - | - | - | - | | [namespace-install.yaml](master/argocd-iac-namespace-install.html) | - | - | - | - | @@ -30,7 +30,7 @@ recent minor releases. | [ui/yarn.lock](v2.5.0-rc3/argocd-test.html) | 0 | 0 | 3 | 0 | | [dex:v2.35.3-distroless](v2.5.0-rc3/ghcr.io_dexidp_dex_v2.35.3-distroless.html) | 0 | 0 | 0 | 0 | | [haproxy:2.6.2-alpine](v2.5.0-rc3/haproxy_2.6.2-alpine.html) | 0 | 0 | 0 | 0 | -| [argocd:v2.5.0-rc3](v2.5.0-rc3/quay.io_argoproj_argocd_v2.5.0-rc3.html) | 0 | 1 | 4 | 13 | +| [argocd:v2.5.0-rc3](v2.5.0-rc3/quay.io_argoproj_argocd_v2.5.0-rc3.html) | 0 | 1 | 8 | 13 | | [redis:7.0.5-alpine](v2.5.0-rc3/redis_7.0.5-alpine.html) | 0 | 0 | 0 | 0 | | [install.yaml](v2.5.0-rc3/argocd-iac-install.html) | - | - | - | - | | [namespace-install.yaml](v2.5.0-rc3/argocd-iac-namespace-install.html) | - | - | - | - | @@ -43,7 +43,7 @@ recent minor releases. | [ui/yarn.lock](v2.4.15/argocd-test.html) | 0 | 0 | 3 | 0 | | [dex:v2.35.3-distroless](v2.4.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html) | 0 | 0 | 0 | 0 | | [haproxy:2.0.29-alpine](v2.4.15/haproxy_2.0.29-alpine.html) | 0 | 0 | 0 | 0 | -| [argocd:v2.4.15](v2.4.15/quay.io_argoproj_argocd_v2.4.15.html) | 0 | 1 | 3 | 13 | +| [argocd:v2.4.15](v2.4.15/quay.io_argoproj_argocd_v2.4.15.html) | 0 | 1 | 7 | 13 | | [redis:7.0.4-alpine](v2.4.15/redis_7.0.4-alpine.html) | 0 | 0 | 0 | 0 | | [install.yaml](v2.4.15/argocd-iac-install.html) | - | - | - | - | | [namespace-install.yaml](v2.4.15/argocd-iac-namespace-install.html) | - | - | - | - | @@ -57,7 +57,7 @@ recent minor releases. | [dex:v2.35.3-distroless](v2.3.10/ghcr.io_dexidp_dex_v2.35.3-distroless.html) | 0 | 0 | 0 | 0 | | [haproxy:2.0.29-alpine](v2.3.10/haproxy_2.0.29-alpine.html) | 0 | 0 | 0 | 0 | | [argocd-applicationset:v0.4.1](v2.3.10/quay.io_argoproj_argocd-applicationset_v0.4.1.html) | 0 | 4 | 38 | 29 | -| [argocd:v2.3.10](v2.3.10/quay.io_argoproj_argocd_v2.3.10.html) | 0 | 1 | 3 | 13 | +| [argocd:v2.3.10](v2.3.10/quay.io_argoproj_argocd_v2.3.10.html) | 0 | 1 | 7 | 13 | | [redis:6.2.7-alpine](v2.3.10/redis_6.2.7-alpine.html) | 0 | 0 | 0 | 0 | | [install.yaml](v2.3.10/argocd-iac-install.html) | - | - | - | - | | [namespace-install.yaml](v2.3.10/argocd-iac-namespace-install.html) | - | - | - | - | @@ -70,7 +70,7 @@ recent minor releases. | [ui/yarn.lock](v2.2.15/argocd-test.html) | 0 | 1 | 5 | 0 | | [dex:v2.35.3-distroless](v2.2.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html) | 0 | 0 | 0 | 0 | | [haproxy:2.0.29-alpine](v2.2.15/haproxy_2.0.29-alpine.html) | 0 | 0 | 0 | 0 | -| [argocd:v2.2.15](v2.2.15/quay.io_argoproj_argocd_v2.2.15.html) | 0 | 1 | 3 | 23 | +| [argocd:v2.2.15](v2.2.15/quay.io_argoproj_argocd_v2.2.15.html) | 0 | 1 | 7 | 23 | | [redis:6.2.7-alpine](v2.2.15/redis_6.2.7-alpine.html) | 0 | 0 | 0 | 0 | | [install.yaml](v2.2.15/argocd-iac-install.html) | - | - | - | - | | [namespace-install.yaml](v2.2.15/argocd-iac-namespace-install.html) | - | - | - | - | diff --git a/docs/snyk/master/argocd-iac-install.html b/docs/snyk/master/argocd-iac-install.html index 8993519bb997a..386e75e842964 100644 --- a/docs/snyk/master/argocd-iac-install.html +++ b/docs/snyk/master/argocd-iac-install.html @@ -456,7 +456,7 @@

Snyk test report

-

October 23rd 2022, 12:44:06 am

+

October 30th 2022, 12:21:01 am

Scanned the following path: diff --git a/docs/snyk/master/argocd-iac-namespace-install.html b/docs/snyk/master/argocd-iac-namespace-install.html index b40cdd7a4d9b9..8f20d3c65098d 100644 --- a/docs/snyk/master/argocd-iac-namespace-install.html +++ b/docs/snyk/master/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

Snyk test report

-

October 23rd 2022, 12:44:18 am

+

October 30th 2022, 12:21:12 am

Scanned the following path: diff --git a/docs/snyk/master/argocd-test.html b/docs/snyk/master/argocd-test.html index 4080861775ec2..bc885d3696896 100644 --- a/docs/snyk/master/argocd-test.html +++ b/docs/snyk/master/argocd-test.html @@ -456,7 +456,7 @@

Snyk test report

-

October 23rd 2022, 12:42:07 am

+

October 30th 2022, 12:19:12 am

Scanned the following paths: diff --git a/docs/snyk/master/ghcr.io_dexidp_dex_v2.35.3-distroless.html b/docs/snyk/master/ghcr.io_dexidp_dex_v2.35.3-distroless.html index 19966331c6934..0e542ba18702f 100644 --- a/docs/snyk/master/ghcr.io_dexidp_dex_v2.35.3-distroless.html +++ b/docs/snyk/master/ghcr.io_dexidp_dex_v2.35.3-distroless.html @@ -456,7 +456,7 @@

Snyk test report

-

October 23rd 2022, 12:42:18 am

+

October 30th 2022, 12:19:27 am

Scanned the following path: diff --git a/docs/snyk/master/haproxy_2.6.2-alpine.html b/docs/snyk/master/haproxy_2.6.2-alpine.html index 8a7089252cd90..ac34b0a807ee4 100644 --- a/docs/snyk/master/haproxy_2.6.2-alpine.html +++ b/docs/snyk/master/haproxy_2.6.2-alpine.html @@ -456,7 +456,7 @@

Snyk test report

-

October 23rd 2022, 12:42:23 am

+

October 30th 2022, 12:19:33 am

Scanned the following path: diff --git a/docs/snyk/master/quay.io_argoproj_argocd_latest.html b/docs/snyk/master/quay.io_argoproj_argocd_latest.html index 3c89d8826d37d..0b388b871837f 100644 --- a/docs/snyk/master/quay.io_argoproj_argocd_latest.html +++ b/docs/snyk/master/quay.io_argoproj_argocd_latest.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

Snyk test report

-

October 23rd 2022, 12:42:50 am

+

October 30th 2022, 12:19:54 am

Scanned the following path: @@ -466,8 +466,8 @@

Snyk test report

-
13 known vulnerabilities
-
83 vulnerable dependency paths
+
14 known vulnerabilities
+
84 vulnerable dependency paths
162 dependencies
@@ -485,6 +485,78 @@

Snyk test report

+
+

Improper Validation of Array Index

+
+ +
+ medium severity +
+ +
+ +
    +
  • + Package Manager: ubuntu:22.04 +
  • +
  • + Vulnerable module: + + sqlite3/libsqlite3-0 +
  • + +
  • Introduced through: + + + docker-image|quay.io/argoproj/argocd@latest, gnupg2/gpg@2.2.27-3ubuntu2.1 and others +
  • +
+ +
+ + +

Detailed paths

+ +
    +
  • + Introduced through: + docker-image|quay.io/argoproj/argocd@latest + + gnupg2/gpg@2.2.27-3ubuntu2.1 + + sqlite3/libsqlite3-0@3.37.2-2 + + + +
  • +
+ +
+ +
+ +

NVD Description

+

Note: Versions mentioned in the description apply to the upstream sqlite3 package.

+

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

+

Remediation

+

There is no fixed version for Ubuntu:22.04 sqlite3.

+

References

+ + +
+ + + +

Time-of-check Time-of-use (TOCTOU)

@@ -571,11 +643,11 @@

Remediation

There is no fixed version for Ubuntu:22.04 shadow.

References


@@ -651,12 +723,12 @@

Remediation

There is no fixed version for Ubuntu:22.04 pcre3.

References


@@ -787,13 +859,13 @@

Remediation

There is no fixed version for Ubuntu:22.04 patch.

References


@@ -897,7 +969,7 @@

Detailed paths

git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 libssh/libssh-4@0.9.6-2build1 @@ -965,6 +1037,7 @@

References

  • ADVISORY
  • CONFIRM
  • CONFIRM
  • +
  • CONFIRM

  • @@ -1372,6 +1445,7 @@

    References

  • ADVISORY
  • MISC
  • MISC
  • +
  • CONFIRM

  • @@ -1523,7 +1597,7 @@

    Detailed paths

    git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 krb5/libgssapi-krb5-2@1.19.2-2 @@ -1536,7 +1610,7 @@

    Detailed paths

    git@1:2.34.1-1ubuntu1.5 - curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + curl/libcurl3-gnutls@7.81.0-1ubuntu1.6 libssh/libssh-4@0.9.6-2build1 @@ -2126,9 +2200,9 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 git.

    References


    @@ -2193,11 +2267,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 coreutils.

    References


    diff --git a/docs/snyk/master/redis_7.0.5-alpine.html b/docs/snyk/master/redis_7.0.5-alpine.html index f8b7ca6a7719a..b841339c1dc2d 100644 --- a/docs/snyk/master/redis_7.0.5-alpine.html +++ b/docs/snyk/master/redis_7.0.5-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:42:58 am

    +

    October 30th 2022, 12:19:59 am

    Scanned the following path: diff --git a/docs/snyk/v2.2.15/argocd-iac-install.html b/docs/snyk/v2.2.15/argocd-iac-install.html index 954c26f6eda36..a0edf272b5831 100644 --- a/docs/snyk/v2.2.15/argocd-iac-install.html +++ b/docs/snyk/v2.2.15/argocd-iac-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:53:16 am

    +

    October 30th 2022, 12:29:41 am

    Scanned the following path: diff --git a/docs/snyk/v2.2.15/argocd-iac-namespace-install.html b/docs/snyk/v2.2.15/argocd-iac-namespace-install.html index 52e40e4fa86ee..5b87513e90510 100644 --- a/docs/snyk/v2.2.15/argocd-iac-namespace-install.html +++ b/docs/snyk/v2.2.15/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:53:23 am

    +

    October 30th 2022, 12:29:48 am

    Scanned the following path: diff --git a/docs/snyk/v2.2.15/argocd-test.html b/docs/snyk/v2.2.15/argocd-test.html index 0a5c1bbe24414..d84197a2ddc0b 100644 --- a/docs/snyk/v2.2.15/argocd-test.html +++ b/docs/snyk/v2.2.15/argocd-test.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:51:59 am

    +

    October 30th 2022, 12:28:26 am

    Scanned the following paths: diff --git a/docs/snyk/v2.2.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html b/docs/snyk/v2.2.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html index d06bf41337b64..6abcdafd65e97 100644 --- a/docs/snyk/v2.2.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html +++ b/docs/snyk/v2.2.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:52:05 am

    +

    October 30th 2022, 12:28:32 am

    Scanned the following path: diff --git a/docs/snyk/v2.2.15/haproxy_2.0.29-alpine.html b/docs/snyk/v2.2.15/haproxy_2.0.29-alpine.html index ae54932d2e96d..2108264cc7bfb 100644 --- a/docs/snyk/v2.2.15/haproxy_2.0.29-alpine.html +++ b/docs/snyk/v2.2.15/haproxy_2.0.29-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:52:07 am

    +

    October 30th 2022, 12:28:35 am

    Scanned the following path: diff --git a/docs/snyk/v2.2.15/quay.io_argoproj_argocd_v2.2.15.html b/docs/snyk/v2.2.15/quay.io_argoproj_argocd_v2.2.15.html index e3629feb4aaae..5031a890611f9 100644 --- a/docs/snyk/v2.2.15/quay.io_argoproj_argocd_v2.2.15.html +++ b/docs/snyk/v2.2.15/quay.io_argoproj_argocd_v2.2.15.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:52:53 am

    +

    October 30th 2022, 12:29:20 am

    Scanned the following path: @@ -466,8 +466,8 @@

    Snyk test report

    -
    27 known vulnerabilities
    -
    208 vulnerable dependency paths
    +
    31 known vulnerabilities
    +
    213 vulnerable dependency paths
    253 dependencies
    @@ -585,6 +585,93 @@

    References

    More about this vulnerability

    +
    +
    +

    Improper Validation of Array Index

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + sqlite3/libsqlite3-0 +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.2.15, gnupg2/gpg@2.2.27-3ubuntu2.1 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.2.15 + + gnupg2/gpg@2.2.27-3ubuntu2.1 + + sqlite3/libsqlite3-0@3.37.2-2 + + + +
    • +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.2.15 + + python3-defaults/libpython3-dev@3.10.6-1~22.04 + + python3.10/libpython3.10-dev@3.10.6-1~22.04 + + python3.10/libpython3.10-stdlib@3.10.6-1~22.04 + + sqlite3/libsqlite3-0@3.37.2-2 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream sqlite3 package.

    +

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

    +

    Remediation

    +

    There is no fixed version for Ubuntu:22.04 sqlite3.

    +

    References

    + + +
    + + +

    Improper Verification of Cryptographic Signature

    @@ -894,6 +981,207 @@

    References

    More about this vulnerability

    +
    +
    +

    CVE-2022-42916

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.2.15, git@1:2.34.1-1ubuntu1.5 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.2.15 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream curl package. + See How to fix? for Ubuntu:22.04 relevant versions.

    +

    In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + + +
    +
    +

    CVE-2022-42915

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.2.15, git@1:2.34.1-1ubuntu1.5 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.2.15 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    This vulnerability has not been analyzed by NVD yet.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + + +
    +
    +

    CVE-2022-32221

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.2.15, git@1:2.34.1-1ubuntu1.5 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.2.15 + + git@1:2.34.1-1ubuntu1.5 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    This vulnerability has not been analyzed by NVD yet.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + +

    Out-of-bounds Write

    @@ -1298,10 +1586,10 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 tiff.

    References


    @@ -1397,11 +1685,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 shadow.

    References


    @@ -1723,6 +2011,10 @@

    References

  • FEDORA
  • FEDORA
  • FEDORA
  • +
  • FEDORA
  • +
  • FEDORA
  • +
  • FEDORA
  • +
  • FEDORA

  • @@ -1798,12 +2090,12 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 pcre3.

    References


    @@ -1960,13 +2252,13 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 patch.

    References


    @@ -2049,6 +2341,7 @@

    References

  • ADVISORY
  • CONFIRM
  • CONFIRM
  • +
  • CONFIRM

  • @@ -2355,6 +2648,7 @@

    References

  • ADVISORY
  • MISC
  • MISC
  • +
  • CONFIRM

  • @@ -2697,11 +2991,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 jbigkit.

    References


    @@ -3329,9 +3623,9 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 git.

    References


    @@ -3409,11 +3703,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 coreutils.

    References


    @@ -3919,11 +4213,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 binutils.

    References


    @@ -4429,9 +4723,9 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 binutils.

    References


    diff --git a/docs/snyk/v2.2.15/redis_6.2.7-alpine.html b/docs/snyk/v2.2.15/redis_6.2.7-alpine.html index bcca6e602cbb2..e2c4c7b47e9bd 100644 --- a/docs/snyk/v2.2.15/redis_6.2.7-alpine.html +++ b/docs/snyk/v2.2.15/redis_6.2.7-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:52:56 am

    +

    October 30th 2022, 12:29:23 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.10/argocd-iac-install.html b/docs/snyk/v2.3.10/argocd-iac-install.html index 10d16ff6d8fea..65c9b917ebdd4 100644 --- a/docs/snyk/v2.3.10/argocd-iac-install.html +++ b/docs/snyk/v2.3.10/argocd-iac-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:50:54 am

    +

    October 30th 2022, 12:27:23 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.10/argocd-iac-namespace-install.html b/docs/snyk/v2.3.10/argocd-iac-namespace-install.html index 20b5ac35220b5..3156dbd1385e1 100644 --- a/docs/snyk/v2.3.10/argocd-iac-namespace-install.html +++ b/docs/snyk/v2.3.10/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:51:36 am

    +

    October 30th 2022, 12:28:00 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.10/argocd-test.html b/docs/snyk/v2.3.10/argocd-test.html index fae1b6663d873..51460380dcd5b 100644 --- a/docs/snyk/v2.3.10/argocd-test.html +++ b/docs/snyk/v2.3.10/argocd-test.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:48:51 am

    +

    October 30th 2022, 12:25:27 am

    Scanned the following paths: diff --git a/docs/snyk/v2.3.10/ghcr.io_dexidp_dex_v2.35.3-distroless.html b/docs/snyk/v2.3.10/ghcr.io_dexidp_dex_v2.35.3-distroless.html index ca048f4429c47..a8415413a91a1 100644 --- a/docs/snyk/v2.3.10/ghcr.io_dexidp_dex_v2.35.3-distroless.html +++ b/docs/snyk/v2.3.10/ghcr.io_dexidp_dex_v2.35.3-distroless.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:48:57 am

    +

    October 30th 2022, 12:25:32 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.10/haproxy_2.0.29-alpine.html b/docs/snyk/v2.3.10/haproxy_2.0.29-alpine.html index 696960a669055..edf2b4dbe8019 100644 --- a/docs/snyk/v2.3.10/haproxy_2.0.29-alpine.html +++ b/docs/snyk/v2.3.10/haproxy_2.0.29-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:49:00 am

    +

    October 30th 2022, 12:25:35 am

    Scanned the following path: diff --git a/docs/snyk/v2.3.10/quay.io_argoproj_argocd-applicationset_v0.4.1.html b/docs/snyk/v2.3.10/quay.io_argoproj_argocd-applicationset_v0.4.1.html index 8e1cc2f8130e6..24bca8a37301f 100644 --- a/docs/snyk/v2.3.10/quay.io_argoproj_argocd-applicationset_v0.4.1.html +++ b/docs/snyk/v2.3.10/quay.io_argoproj_argocd-applicationset_v0.4.1.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:49:16 am

    +

    October 30th 2022, 12:25:50 am

    Scanned the following path: @@ -4947,6 +4947,7 @@

    References

  • DEBIAN
  • MLIST
  • CONFIRM
  • +
  • CONFIRM

  • @@ -5019,6 +5020,7 @@

    References

  • FEDORA
  • DEBIAN
  • CONFIRM
  • +
  • CONFIRM

  • @@ -5092,6 +5094,7 @@

    References

  • DEBIAN
  • MLIST
  • CONFIRM
  • +
  • CONFIRM

  • @@ -5164,6 +5167,7 @@

    References

  • FEDORA
  • DEBIAN
  • CONFIRM
  • +
  • CONFIRM

  • @@ -5308,6 +5312,10 @@

    References

  • ADVISORY
  • MISC
  • N/A
  • +
  • CONFIRM
  • +
  • CONFIRM
  • +
  • CONFIRM
  • +
  • CONFIRM

  • @@ -5566,11 +5574,11 @@

    Remediation

    There is no fixed version for Ubuntu:21.10 shadow.

    References


    @@ -5731,12 +5739,12 @@

    Remediation

    There is no fixed version for Ubuntu:21.10 pcre3.

    References


    @@ -5810,6 +5818,7 @@

    References

  • FEDORA
  • FEDORA
  • FEDORA
  • +
  • CONFIRM

  • @@ -5884,6 +5893,7 @@

    References

  • FEDORA
  • FEDORA
  • FEDORA
  • +
  • CONFIRM

  • @@ -5948,13 +5958,13 @@

    Remediation

    There is no fixed version for Ubuntu:21.10 patch.

    References


    @@ -6430,6 +6440,7 @@

    References

  • ADVISORY
  • MISC
  • MISC
  • +
  • CONFIRM

  • @@ -7445,9 +7456,9 @@

    Remediation

    There is no fixed version for Ubuntu:21.10 git.

    References


    @@ -7806,11 +7817,11 @@

    Remediation

    There is no fixed version for Ubuntu:21.10 coreutils.

    References


    diff --git a/docs/snyk/v2.3.10/quay.io_argoproj_argocd_v2.3.10.html b/docs/snyk/v2.3.10/quay.io_argoproj_argocd_v2.3.10.html index e148b8af8fa69..c5967593735df 100644 --- a/docs/snyk/v2.3.10/quay.io_argoproj_argocd_v2.3.10.html +++ b/docs/snyk/v2.3.10/quay.io_argoproj_argocd_v2.3.10.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:49:47 am

    +

    October 30th 2022, 12:26:21 am

    Scanned the following path: @@ -466,8 +466,8 @@

    Snyk test report

    -
    17 known vulnerabilities
    -
    98 vulnerable dependency paths
    +
    21 known vulnerabilities
    +
    102 vulnerable dependency paths
    162 dependencies
    @@ -585,6 +585,78 @@

    References

    More about this vulnerability

    +
    +
    +

    Improper Validation of Array Index

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + sqlite3/libsqlite3-0 +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.3.10, gnupg2/gpg@2.2.27-3ubuntu2.1 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.10 + + gnupg2/gpg@2.2.27-3ubuntu2.1 + + sqlite3/libsqlite3-0@3.37.2-2 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream sqlite3 package.

    +

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

    +

    Remediation

    +

    There is no fixed version for Ubuntu:22.04 sqlite3.

    +

    References

    + + +
    + + +

    Improper Verification of Cryptographic Signature

    @@ -791,6 +863,7 @@

    References


    @@ -880,6 +953,8 @@

    References


    @@ -888,6 +963,207 @@

    References

    More about this vulnerability

    +
    +
    +

    CVE-2022-42916

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.3.10, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.10 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream curl package. + See How to fix? for Ubuntu:22.04 relevant versions.

    +

    In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + + +
    +
    +

    CVE-2022-42915

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.3.10, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.10 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    This vulnerability has not been analyzed by NVD yet.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + + +
    +
    +

    CVE-2022-32221

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.3.10, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.3.10 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    This vulnerability has not been analyzed by NVD yet.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + +

    Time-of-check Time-of-use (TOCTOU)

    @@ -975,11 +1251,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 shadow.

    References


    @@ -1055,12 +1331,12 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 pcre3.

    References


    @@ -1191,13 +1467,13 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 patch.

    References


    @@ -1369,6 +1645,7 @@

    References

  • ADVISORY
  • CONFIRM
  • CONFIRM
  • +
  • CONFIRM

  • @@ -1776,6 +2053,7 @@

    References

  • ADVISORY
  • MISC
  • MISC
  • +
  • CONFIRM

  • @@ -2530,9 +2808,9 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 git.

    References


    @@ -2597,11 +2875,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 coreutils.

    References


    diff --git a/docs/snyk/v2.3.10/redis_6.2.7-alpine.html b/docs/snyk/v2.3.10/redis_6.2.7-alpine.html index eaa0258acad7c..da39c18052fa9 100644 --- a/docs/snyk/v2.3.10/redis_6.2.7-alpine.html +++ b/docs/snyk/v2.3.10/redis_6.2.7-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:49:52 am

    +

    October 30th 2022, 12:26:25 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.15/argocd-iac-install.html b/docs/snyk/v2.4.15/argocd-iac-install.html index 467b1699195d6..2e8f85e06abbb 100644 --- a/docs/snyk/v2.4.15/argocd-iac-install.html +++ b/docs/snyk/v2.4.15/argocd-iac-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:48:26 am

    +

    October 30th 2022, 12:25:04 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.15/argocd-iac-namespace-install.html b/docs/snyk/v2.4.15/argocd-iac-namespace-install.html index 113e7f0fb92d9..d1be6fe914228 100644 --- a/docs/snyk/v2.4.15/argocd-iac-namespace-install.html +++ b/docs/snyk/v2.4.15/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:48:36 am

    +

    October 30th 2022, 12:25:13 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.15/argocd-test.html b/docs/snyk/v2.4.15/argocd-test.html index 9c41f56d040ca..a57aed508e911 100644 --- a/docs/snyk/v2.4.15/argocd-test.html +++ b/docs/snyk/v2.4.15/argocd-test.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:46:44 am

    +

    October 30th 2022, 12:23:29 am

    Scanned the following paths: diff --git a/docs/snyk/v2.4.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html b/docs/snyk/v2.4.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html index fbc6fac58df5b..b437521d1696b 100644 --- a/docs/snyk/v2.4.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html +++ b/docs/snyk/v2.4.15/ghcr.io_dexidp_dex_v2.35.3-distroless.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:46:50 am

    +

    October 30th 2022, 12:23:36 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.15/haproxy_2.0.29-alpine.html b/docs/snyk/v2.4.15/haproxy_2.0.29-alpine.html index a7707a5bf6b40..b3252400d89d1 100644 --- a/docs/snyk/v2.4.15/haproxy_2.0.29-alpine.html +++ b/docs/snyk/v2.4.15/haproxy_2.0.29-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:46:55 am

    +

    October 30th 2022, 12:23:42 am

    Scanned the following path: diff --git a/docs/snyk/v2.4.15/quay.io_argoproj_argocd_v2.4.15.html b/docs/snyk/v2.4.15/quay.io_argoproj_argocd_v2.4.15.html index 91ab541670b28..8381f2c87b862 100644 --- a/docs/snyk/v2.4.15/quay.io_argoproj_argocd_v2.4.15.html +++ b/docs/snyk/v2.4.15/quay.io_argoproj_argocd_v2.4.15.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:47:15 am

    +

    October 30th 2022, 12:24:01 am

    Scanned the following path: @@ -466,8 +466,8 @@

    Snyk test report

    -
    17 known vulnerabilities
    -
    98 vulnerable dependency paths
    +
    21 known vulnerabilities
    +
    102 vulnerable dependency paths
    162 dependencies
    @@ -585,6 +585,78 @@

    References

    More about this vulnerability

    +
    +
    +

    Improper Validation of Array Index

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + sqlite3/libsqlite3-0 +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.4.15, gnupg2/gpg@2.2.27-3ubuntu2.1 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.15 + + gnupg2/gpg@2.2.27-3ubuntu2.1 + + sqlite3/libsqlite3-0@3.37.2-2 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream sqlite3 package.

    +

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

    +

    Remediation

    +

    There is no fixed version for Ubuntu:22.04 sqlite3.

    +

    References

    + + +
    + + +

    Improper Verification of Cryptographic Signature

    @@ -791,6 +863,7 @@

    References


    @@ -880,6 +953,8 @@

    References


    @@ -888,6 +963,207 @@

    References

    More about this vulnerability

    +
    +
    +

    CVE-2022-42916

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.4.15, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.15 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream curl package. + See How to fix? for Ubuntu:22.04 relevant versions.

    +

    In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + + +
    +
    +

    CVE-2022-42915

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.4.15, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.15 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    This vulnerability has not been analyzed by NVD yet.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + + +
    +
    +

    CVE-2022-32221

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.4.15, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.4.15 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    This vulnerability has not been analyzed by NVD yet.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + +

    Time-of-check Time-of-use (TOCTOU)

    @@ -975,11 +1251,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 shadow.

    References


    @@ -1055,12 +1331,12 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 pcre3.

    References


    @@ -1191,13 +1467,13 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 patch.

    References


    @@ -1369,6 +1645,7 @@

    References

  • ADVISORY
  • CONFIRM
  • CONFIRM
  • +
  • CONFIRM

  • @@ -1776,6 +2053,7 @@

    References

  • ADVISORY
  • MISC
  • MISC
  • +
  • CONFIRM

  • @@ -2530,9 +2808,9 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 git.

    References


    @@ -2597,11 +2875,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 coreutils.

    References


    diff --git a/docs/snyk/v2.4.15/redis_7.0.4-alpine.html b/docs/snyk/v2.4.15/redis_7.0.4-alpine.html index 4a3e240aaa0ef..ad1c5cd591c69 100644 --- a/docs/snyk/v2.4.15/redis_7.0.4-alpine.html +++ b/docs/snyk/v2.4.15/redis_7.0.4-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:47:20 am

    +

    October 30th 2022, 12:24:06 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.0-rc3/argocd-iac-install.html b/docs/snyk/v2.5.0-rc3/argocd-iac-install.html index 1383f0cc895f9..d29cae2a9240c 100644 --- a/docs/snyk/v2.5.0-rc3/argocd-iac-install.html +++ b/docs/snyk/v2.5.0-rc3/argocd-iac-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:46:14 am

    +

    October 30th 2022, 12:22:59 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.0-rc3/argocd-iac-namespace-install.html b/docs/snyk/v2.5.0-rc3/argocd-iac-namespace-install.html index 6e44b747ffec6..78a3f0349a1ec 100644 --- a/docs/snyk/v2.5.0-rc3/argocd-iac-namespace-install.html +++ b/docs/snyk/v2.5.0-rc3/argocd-iac-namespace-install.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:46:25 am

    +

    October 30th 2022, 12:23:10 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.0-rc3/argocd-test.html b/docs/snyk/v2.5.0-rc3/argocd-test.html index c6f8dc4e1bcd7..1a400217f9556 100644 --- a/docs/snyk/v2.5.0-rc3/argocd-test.html +++ b/docs/snyk/v2.5.0-rc3/argocd-test.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:44:33 am

    +

    October 30th 2022, 12:21:25 am

    Scanned the following paths: diff --git a/docs/snyk/v2.5.0-rc3/ghcr.io_dexidp_dex_v2.35.3-distroless.html b/docs/snyk/v2.5.0-rc3/ghcr.io_dexidp_dex_v2.35.3-distroless.html index e1d00ab3365f3..668882f2fbd72 100644 --- a/docs/snyk/v2.5.0-rc3/ghcr.io_dexidp_dex_v2.35.3-distroless.html +++ b/docs/snyk/v2.5.0-rc3/ghcr.io_dexidp_dex_v2.35.3-distroless.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:44:37 am

    +

    October 30th 2022, 12:21:29 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.0-rc3/haproxy_2.6.2-alpine.html b/docs/snyk/v2.5.0-rc3/haproxy_2.6.2-alpine.html index 2b68e15bb8ac5..c190ae25c2367 100644 --- a/docs/snyk/v2.5.0-rc3/haproxy_2.6.2-alpine.html +++ b/docs/snyk/v2.5.0-rc3/haproxy_2.6.2-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:44:42 am

    +

    October 30th 2022, 12:21:31 am

    Scanned the following path: diff --git a/docs/snyk/v2.5.0-rc3/quay.io_argoproj_argocd_v2.5.0-rc3.html b/docs/snyk/v2.5.0-rc3/quay.io_argoproj_argocd_v2.5.0-rc3.html index c996a529b2b6f..4133c1c06558c 100644 --- a/docs/snyk/v2.5.0-rc3/quay.io_argoproj_argocd_v2.5.0-rc3.html +++ b/docs/snyk/v2.5.0-rc3/quay.io_argoproj_argocd_v2.5.0-rc3.html @@ -7,7 +7,7 @@ Snyk test report - + @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:45:02 am

    +

    October 30th 2022, 12:21:55 am

    Scanned the following path: @@ -466,8 +466,8 @@

    Snyk test report

    -
    18 known vulnerabilities
    -
    99 vulnerable dependency paths
    +
    22 known vulnerabilities
    +
    103 vulnerable dependency paths
    162 dependencies
    @@ -660,6 +660,12 @@

    References

  • MLIST
  • FEDORA
  • FEDORA
  • +
  • CONFIRM
  • +
  • CONFIRM
  • +
  • CONFIRM
  • +
  • CONFIRM
  • +
  • CONFIRM
  • +
  • CONFIRM

  • @@ -668,6 +674,78 @@

    References

    More about this vulnerability

    +
    +
    +

    Improper Validation of Array Index

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + sqlite3/libsqlite3-0 +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.5.0-rc3, gnupg2/gpg@2.2.27-3ubuntu2.1 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.0-rc3 + + gnupg2/gpg@2.2.27-3ubuntu2.1 + + sqlite3/libsqlite3-0@3.37.2-2 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream sqlite3 package.

    +

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

    +

    Remediation

    +

    There is no fixed version for Ubuntu:22.04 sqlite3.

    +

    References

    + + +
    + + +

    Improper Verification of Cryptographic Signature

    @@ -874,6 +952,7 @@

    References


    @@ -963,6 +1042,8 @@

    References


    @@ -971,6 +1052,207 @@

    References

    More about this vulnerability

    +
    +
    +

    CVE-2022-42916

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.5.0-rc3, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.0-rc3 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    Note: Versions mentioned in the description apply to the upstream curl package. + See How to fix? for Ubuntu:22.04 relevant versions.

    +

    In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + + +
    +
    +

    CVE-2022-42915

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.5.0-rc3, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.0-rc3 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    This vulnerability has not been analyzed by NVD yet.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + + +
    +
    +

    CVE-2022-32221

    +
    + +
    + medium severity +
    + +
    + +
      +
    • + Package Manager: ubuntu:22.04 +
    • +
    • + Vulnerable module: + + curl/libcurl3-gnutls +
    • + +
    • Introduced through: + + + docker-image|quay.io/argoproj/argocd@v2.5.0-rc3, git@1:2.34.1-1ubuntu1.4 and others +
    • +
    + +
    + + +

    Detailed paths

    + +
      +
    • + Introduced through: + docker-image|quay.io/argoproj/argocd@v2.5.0-rc3 + + git@1:2.34.1-1ubuntu1.4 + + curl/libcurl3-gnutls@7.81.0-1ubuntu1.4 + + + +
    • +
    + +
    + +
    + +

    NVD Description

    +

    This vulnerability has not been analyzed by NVD yet.

    +

    Remediation

    +

    Upgrade Ubuntu:22.04 curl to version 7.81.0-1ubuntu1.6 or higher.

    +

    References

    + + +
    + + +

    Time-of-check Time-of-use (TOCTOU)

    @@ -1058,11 +1340,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 shadow.

    References


    @@ -1138,12 +1420,12 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 pcre3.

    References


    @@ -1274,13 +1556,13 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 patch.

    References


    @@ -1452,6 +1734,7 @@

    References

  • ADVISORY
  • CONFIRM
  • CONFIRM
  • +
  • CONFIRM

  • @@ -1859,6 +2142,7 @@

    References

  • ADVISORY
  • MISC
  • MISC
  • +
  • CONFIRM

  • @@ -2613,9 +2897,9 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 git.

    References


    @@ -2680,11 +2964,11 @@

    Remediation

    There is no fixed version for Ubuntu:22.04 coreutils.

    References


    diff --git a/docs/snyk/v2.5.0-rc3/redis_7.0.5-alpine.html b/docs/snyk/v2.5.0-rc3/redis_7.0.5-alpine.html index 22634f68745f8..c5a3ff76bea79 100644 --- a/docs/snyk/v2.5.0-rc3/redis_7.0.5-alpine.html +++ b/docs/snyk/v2.5.0-rc3/redis_7.0.5-alpine.html @@ -456,7 +456,7 @@

    Snyk test report

    -

    October 23rd 2022, 12:45:06 am

    +

    October 30th 2022, 12:21:58 am

    Scanned the following path: