Code Monkey home page Code Monkey logo

docker-molecule's Issues

[CVE-2022-23491] Insufficient Verification of Data Authenticity

Overview

CVE-2022-23491 - The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CVSS

No score yet

Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from TrustCor from the root store. These are in the process of being removed from Mozillas trust store. TrustCors root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCors ownership also operated a business that produced spyware. Conclusions of Mozillas investigation can be found in the linked google group discussion. The fix is to bump package to 2022.12.07.

[CVE-2022-40897] pypa/setuptools vulnerable to Regular Expression Denial of Service

Overview

CVE-2022-40897 - Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page.

CVSS

Base: 7.5 HIGH Trivy list this as high in the pipeline but there isnt a score yet.

Description

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py..

[CVE-2022-43680] expat use after free exploit


Overview

CVE-2022-43680 - In src:expat, an XML parsing C library, there is a use-after free
caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

CVSS

Base: 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

NVD doesnt have it rated yet but Trivy gives it a 7.5.

Description

In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. Fix is to update package to 2.2.10-2+deb11u5.

Workflows are all over the place lol

Hmm not sure about the reusable workflows. Its nice to have them but all the workflows just run independent of each other.

Maybe when the main repo gets setup can maybe handle it better. Not sure if a workflow can be dependent on another one.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.