Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Nexus URL: https://nexus.akraino.org/content/sites/logs/fujitsu/job/sdt/r7/sdt-vuls/1/

There are 5 CVEs with 6 CVEs with a CVSS score >= 9.0.  These These are exceptions requested here:

Release 7: Akraino CVE and KHV Vulnerability Exception Request

CVE-IDCVSSNVDFix/Notes
CVE-2022-364310.0https://nvd.nist.gov/vuln/detail/CVE-2022-3643

Fix not yet available

Ubuntu CVE record

CVE-2016-15859.8https://nvd.nist.gov/vuln/detail/CVE-2016-1585

No fix available

Ubuntu CVE record

CVE-2022-03189.8https://nvd.nist.gov/vuln/detail/CVE-2022-0318

Fix not yet available

Ubuntu CVE record

CVE-2022-1927322219.8https://nvd.nist.gov/vuln/detail/CVE-2022-192732221

TODO: Appears fixedFix not yet available

Ubuntu CVE record

CVE-2022-2038536499.8https://nvd.nist.gov/vuln/detail/CVE-2022-203853649

Fix not yet No fix available

Ubuntu CVE record

CVE-2022-37434406749.8https://nvd.nist.gov/vuln/detail/CVE-2022-3743440674

TODO: Appears fixed

No fix available (for zlib1g, zlib1g-dev)

1:1.2.11.dfsg-2ubuntu1.5 is released, we need to upgrade.  

Ubuntu CVE record

Lynis

Nexus URL (manual run, with fixes): https://nexus.akraino.org/content/sites/logs/fujitsu/job/sdt/r7/sdt-lynis/2/

...