Skip to content

Scheduled CVE vulnerability scan of published images. #32

Scheduled CVE vulnerability scan of published images.

Scheduled CVE vulnerability scan of published images. #32

Manually triggered September 3, 2024 04:12
Status Failure
Total duration 56s
Artifacts

vulnerability-scan.yml

on: workflow_dispatch
setup-matrix
21s
setup-matrix
Matrix: vulnerability-scan-schedule
Fit to window
Zoom out
Zoom in

Annotations

41 errors, 33 warnings, and 1 notice
vulnerability-scan-schedule (mailpit)
2024-09-03T04:13:42Z INFO Need to update DB 2024-09-03T04:13:42Z INFO Downloading DB... repository="ghcr.io/aquasecurity/trivy-db:2" 2024-09-03T04:13:44Z INFO Vulnerability scanning is enabled 2024-09-03T04:13:44Z INFO Secret scanning is enabled 2024-09-03T04:13:44Z INFO If your scanning is slow, please try '--scanners vuln' to disable secret scanning 2024-09-03T04:13:44Z INFO Please see also https://aquasecurity.github.io/trivy/v0.53/docs/scanner/secret#recommendation for faster secret detection 2024-09-03T04:13:44Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/mailpit:5.x" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred: * docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/mailpit:5.x): Error response from daemon: No such image: ghcr.io/dpc-sdp/bay/mailpit:5.x * containerd error: failed to initialize a containerd client: failed to dial "/run/containerd/containerd.sock": connection error: desc = "transport: error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied" * podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/mailpit:5.x): failed to find image ghcr.io/dpc-sdp/bay/mailpit:5.x: ghcr.io/dpc-sdp/bay/mailpit:5.x: No such image * remote error: GET https://ghcr.io/v2/dpc-sdp/bay/mailpit/manifests/5.x: MANIFEST_UNKNOWN: manifest unknown
vulnerability-scan-schedule (awx-ee)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (awx-ee)
The operation was canceled.
vulnerability-scan-schedule (mariadb)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (mariadb)
CVE-2022-37434 - CRITICAL severity - zlib: heap-based buffer over-read and overflow in inflate() in inflate.c via a large gzip header extra field vulnerability in zlib
vulnerability-scan-schedule (mariadb)
CVE-2024-24790 - CRITICAL severity - golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2023-45283 - HIGH severity - The filepath package does not recognize paths with a \??\ prefix as sp ... vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2023-45288 - HIGH severity - golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS vulnerability in stdlib
vulnerability-scan-schedule (ci-builder)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (ci-builder)
The operation was canceled.
vulnerability-scan-schedule (mariadb)
CVE-2024-24790 - CRITICAL severity - golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2023-45288 - HIGH severity - golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
The operation was canceled.
vulnerability-scan-schedule (nginx)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (nginx)
The operation was canceled.
vulnerability-scan-schedule (nginx)
CVE-2023-52425 - HIGH severity - expat: parsing large tokens can trigger a denial of service vulnerability in libexpat
vulnerability-scan-schedule (nginx)
CVE-2024-28757 - HIGH severity - expat: XML Entity Expansion vulnerability in libexpat
vulnerability-scan-schedule (nginx)
CVE-2024-25062 - HIGH severity - libxml2: use-after-free in XMLReader vulnerability in libxml2
vulnerability-scan-schedule (nginx)
CVE-2024-24790 - CRITICAL severity - golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses vulnerability in stdlib
vulnerability-scan-schedule (nginx)
CVE-2023-45283 - HIGH severity - The filepath package does not recognize paths with a \??\ prefix as sp ... vulnerability in stdlib
vulnerability-scan-schedule (nginx)
CVE-2023-45288 - HIGH severity - golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS vulnerability in stdlib
vulnerability-scan-schedule (node)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (nginx)
CVE-2024-24790 - CRITICAL severity - golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses vulnerability in stdlib
vulnerability-scan-schedule (nginx)
CVE-2023-45283 - HIGH severity - The filepath package does not recognize paths with a \??\ prefix as sp ... vulnerability in stdlib
vulnerability-scan-schedule (node)
The operation was canceled.
vulnerability-scan-schedule (nginx)
CVE-2023-45288 - HIGH severity - golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2024-24790 - CRITICAL severity - golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2023-45283 - HIGH severity - The filepath package does not recognize paths with a \??\ prefix as sp ... vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2023-45288 - HIGH severity - golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2024-24790 - CRITICAL severity - golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2023-45288 - HIGH severity - golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS vulnerability in stdlib
vulnerability-scan-schedule (php-cli)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (php-cli)
The operation was canceled.
vulnerability-scan-schedule (elasticsearch)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (elasticsearch)
The operation was canceled.
vulnerability-scan-schedule (php-fpm)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (php-fpm)
The operation was canceled.
vulnerability-scan-schedule (ripple-static)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (ripple-static)
The operation was canceled.
vulnerability-scan-schedule (mailhog)
The job was canceled because "mailpit" failed.
vulnerability-scan-schedule (mailhog)
The operation was canceled.
vulnerability-scan-schedule (mariadb)
CVE-2023-39326 - MEDIUM severity - golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2023-45284 - MEDIUM severity - On Windows, The IsLocal function does not correctly detect reserved de ... vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2023-45289 - MEDIUM severity - golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2023-45290 - MEDIUM severity - golang: net/http: memory exhaustion in Request.ParseMultipartForm vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2024-24783 - MEDIUM severity - golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2024-24784 - MEDIUM severity - golang: net/mail: comments in display names are incorrectly handled vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2024-24785 - MEDIUM severity - golang: html/template: errors returned from MarshalJSON methods may break template escaping vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2024-24789 - MEDIUM severity - golang: archive/zip: Incorrect handling of certain ZIP files vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2024-24791 - MEDIUM severity - net/http: Denial of service due to improper 100-continue handling in net/http vulnerability in stdlib
vulnerability-scan-schedule (mariadb)
CVE-2024-24786 - MEDIUM severity - golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON vulnerability in google.golang.org/protobuf
vulnerability-scan-schedule (mariadb)
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
vulnerability-scan-schedule (nginx)
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
vulnerability-scan-schedule (nginx)
CVE-2023-42363 - MEDIUM severity - busybox: use-after-free in awk vulnerability in busybox
vulnerability-scan-schedule (nginx)
CVE-2023-42364 - MEDIUM severity - busybox: use-after-free vulnerability in busybox
vulnerability-scan-schedule (nginx)
CVE-2023-42365 - MEDIUM severity - busybox: use-after-free vulnerability in busybox
vulnerability-scan-schedule (nginx)
CVE-2023-42366 - MEDIUM severity - busybox: A heap-buffer-overflow vulnerability in busybox
vulnerability-scan-schedule (nginx)
CVE-2023-42363 - MEDIUM severity - busybox: use-after-free in awk vulnerability in busybox-binsh
vulnerability-scan-schedule (nginx)
CVE-2023-42364 - MEDIUM severity - busybox: use-after-free vulnerability in busybox-binsh
vulnerability-scan-schedule (nginx)
CVE-2023-42365 - MEDIUM severity - busybox: use-after-free vulnerability in busybox-binsh
vulnerability-scan-schedule (nginx)
CVE-2023-42366 - MEDIUM severity - busybox: A heap-buffer-overflow vulnerability in busybox-binsh
vulnerability-scan-schedule (nginx)
CVE-2024-4603 - MEDIUM severity - openssl: Excessive time spent checking DSA keys and parameters vulnerability in libcrypto3
vulnerability-scan-schedule (nginx)
CVE-2024-4741 - MEDIUM severity - openssl: Use After Free with SSL_free_buffers vulnerability in libcrypto3
vulnerability-scan-schedule (node)
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
vulnerability-scan-schedule (node)
CVE-2023-39326 - MEDIUM severity - golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2023-45284 - MEDIUM severity - On Windows, The IsLocal function does not correctly detect reserved de ... vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2023-45289 - MEDIUM severity - golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2023-45290 - MEDIUM severity - golang: net/http: memory exhaustion in Request.ParseMultipartForm vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2024-24783 - MEDIUM severity - golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2024-24784 - MEDIUM severity - golang: net/mail: comments in display names are incorrectly handled vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2024-24785 - MEDIUM severity - golang: html/template: errors returned from MarshalJSON methods may break template escaping vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2024-24789 - MEDIUM severity - golang: archive/zip: Incorrect handling of certain ZIP files vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2024-24791 - MEDIUM severity - net/http: Denial of service due to improper 100-continue handling in net/http vulnerability in stdlib
vulnerability-scan-schedule (node)
CVE-2024-24786 - MEDIUM severity - golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON vulnerability in google.golang.org/protobuf
vulnerability-scan-schedule (nginx)
CVE-2024-1580 - UNKNOWN severity - An integer overflow in dav1d AV1 decoder that can occur when decoding ... vulnerability in libdav1d