Unpacked Filesystem

    1. 2021-03-08T05:22:26.380Z INFO Downloading DB...
    2. 20.37 MiB / 20.37 MiB [-------------------------------------------------------------------------------------------------------------------------------------] 100.00% 8.24 MiB p/s 2s
    3. 2021-03-08T05:22:30.134Z INFO Detecting Alpine vulnerabilities...
    4. /tmp/rootfs (alpine 3.10.2)
    5. ===========================
    6. Total: 20 (UNKNOWN: 0, LOW: 2, MEDIUM: 10, HIGH: 8, CRITICAL: 0)
    7. +--------------+------------------+----------+-------------------+---------------+---------------------------------------+
    8. | LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE |
    9. +--------------+------------------+----------+-------------------+---------------+---------------------------------------+
    10. | libcrypto1.1 | CVE-2020-1967 | HIGH | 1.1.1c-r0 | 1.1.1g-r0 | openssl: Segmentation |
    11. | | | | | | fault in SSL_check_chain |
    12. | | | | | | causes denial of service |
    13. | | | | | | -->avd.aquasec.com/nvd/cve-2020-1967 |
    14. + +------------------+ + +---------------+---------------------------------------+
    15. | | CVE-2021-23839 | | | 1.1.1j-r0 | openssl: incorrect SSLv2 |
    16. | | | | | | rollback protection |
    17. | | | | | | -->avd.aquasec.com/nvd/cve-2021-23839 |
    18. + +------------------+ + + +---------------------------------------+
    19. | | CVE-2021-23840 | | | | openssl: integer |
    20. | | | | | | overflow in CipherUpdate |
    21. | | | | | | -->avd.aquasec.com/nvd/cve-2021-23840 |
    22. + +------------------+ + + +---------------------------------------+
    23. | | CVE-2021-23841 | | | | openssl: NULL pointer dereference |
    24. | | | | | | in X509_issuer_and_serial_hash() |
    25. | | | | | | -->avd.aquasec.com/nvd/cve-2021-23841 |
    26. + +------------------+----------+ +---------------+---------------------------------------+
    27. | | CVE-2019-1547 | MEDIUM | | 1.1.1d-r0 | openssl: side-channel weak |
    28. | | | | | | encryption vulnerability |
    29. | | | | | | -->avd.aquasec.com/nvd/cve-2019-1547 |
    30. | | CVE-2019-1549 | | | | openssl: information |
    31. | | | | | | disclosure in fork() |
    32. | | | | | | -->avd.aquasec.com/nvd/cve-2019-1549 |
    33. + +------------------+ + +---------------+---------------------------------------+
    34. | | CVE-2019-1551 | | | 1.1.1d-r2 | openssl: Integer overflow in RSAZ |
    35. | | | | | | modular exponentiation on x86_64 |
    36. | | | | | | -->avd.aquasec.com/nvd/cve-2019-1551 |
    37. + +------------------+ + +---------------+---------------------------------------+
    38. | | CVE-2020-1971 | | | 1.1.1i-r0 | openssl: EDIPARTYNAME |
    39. | | | | | | NULL pointer de-reference |
    40. | | | | | | -->avd.aquasec.com/nvd/cve-2020-1971 |
    41. + +------------------+----------+ +---------------+---------------------------------------+
    42. | | CVE-2019-1563 | LOW | | 1.1.1d-r0 | openssl: information |
    43. | | | | | | disclosure in PKCS7_dataDecode |
    44. | | | | | | and CMS_decrypt_set1_pkey |
    45. | | | | | | -->avd.aquasec.com/nvd/cve-2019-1563 |
    46. +--------------+------------------+----------+ +---------------+---------------------------------------+
    47. | libssl1.1 | CVE-2020-1967 | HIGH | | 1.1.1g-r0 | openssl: Segmentation |
    48. | | | | | | fault in SSL_check_chain |
    49. | | | | | | causes denial of service |
    50. | | | | | | -->avd.aquasec.com/nvd/cve-2020-1967 |
    51. + +------------------+ + +---------------+---------------------------------------+
    52. | | CVE-2021-23839 | | | 1.1.1j-r0 | openssl: incorrect SSLv2 |
    53. | | | | | | rollback protection |
    54. | | | | | | -->avd.aquasec.com/nvd/cve-2021-23839 |
    55. + +------------------+ + + +---------------------------------------+
    56. | | CVE-2021-23840 | | | | openssl: integer |
    57. | | | | | | overflow in CipherUpdate |
    58. | | | | | | -->avd.aquasec.com/nvd/cve-2021-23840 |
    59. + +------------------+ + + +---------------------------------------+
    60. | | CVE-2021-23841 | | | | openssl: NULL pointer dereference |
    61. + +------------------+----------+ +---------------+---------------------------------------+
    62. | | CVE-2019-1547 | MEDIUM | | 1.1.1d-r0 | openssl: side-channel weak |
    63. | | | | | | encryption vulnerability |
    64. | | | | | | -->avd.aquasec.com/nvd/cve-2019-1547 |
    65. + +------------------+ + + +---------------------------------------+
    66. | | CVE-2019-1549 | | | | openssl: information |
    67. | | | | | | disclosure in fork() |
    68. | | | | | | -->avd.aquasec.com/nvd/cve-2019-1549 |
    69. + +------------------+ + +---------------+---------------------------------------+
    70. | | CVE-2019-1551 | | | 1.1.1d-r2 | openssl: Integer overflow in RSAZ |
    71. | | | | | | modular exponentiation on x86_64 |
    72. | | | | | | -->avd.aquasec.com/nvd/cve-2019-1551 |
    73. + +------------------+ + +---------------+---------------------------------------+
    74. | | CVE-2020-1971 | | | 1.1.1i-r0 | openssl: EDIPARTYNAME |
    75. | | | | | | NULL pointer de-reference |
    76. | | | | | | -->avd.aquasec.com/nvd/cve-2020-1971 |
    77. + +------------------+----------+ +---------------+---------------------------------------+
    78. | | CVE-2019-1563 | LOW | | 1.1.1d-r0 | openssl: information |
    79. | | | | | | disclosure in PKCS7_dataDecode |
    80. | | | | | | and CMS_decrypt_set1_pkey |
    81. | | | | | | -->avd.aquasec.com/nvd/cve-2019-1563 |
    82. +--------------+------------------+----------+-------------------+---------------+---------------------------------------+
    83. | musl | CVE-2020-28928 | MEDIUM | 1.1.22-r3 | 1.1.22-r4 | In musl libc through 1.2.1, |
    84. | | | | | | wcsnrtombs mishandles particular |
    85. | | | | | | combinations of destination buffer... |
    86. | | | | | | -->avd.aquasec.com/nvd/cve-2020-28928 |
    87. +--------------+ + + + + +
    88. | musl-utils | | | | | |
    89. | | | | | | |
    90. | | | | | | |
    91. +--------------+------------------+----------+-------------------+---------------+---------------------------------------+