Skip to content

Run Image Scan for Amazon CloudWatch Observability Helm Chart #55

Run Image Scan for Amazon CloudWatch Observability Helm Chart

Run Image Scan for Amazon CloudWatch Observability Helm Chart #55

Manually triggered December 3, 2024 18:52
Status Failure
Total duration 43s
Artifacts
Matrix: ContainerImageScan
Fit to window
Zoom out
Zoom in

Annotations

28 errors, 31 warnings, and 10 notices
ContainerImageScan (.dcgmExporter.image.repositoryDomainMap.public, .dcgmExporter.image.repositor...
2024-12-03T18:52:31Z INFO [vulndb] Need to update DB 2024-12-03T18:52:31Z INFO [vulndb] Downloading vulnerability DB... 2024-12-03T18:52:31Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2" 2024-12-03T18:52:33Z FATAL Fatal error init error: DB error: failed to download vulnerability DB: OCI artifact error: failed to download vulnerability DB: failed to download artifact from mirror.gcr.io/aquasec/trivy-db:2: oci download error: failed to fetch the layer: GET https://mirror.gcr.io/v2/aquasec/trivy-db/blobs/sha256:091a07a2add2ec3fc0605fd2b57fb265cf7a79ac70a39b5dedfde1588329c24a: BLOB_UNKNOWN: Unknown blob: sha256:091a07a2add2ec3fc0605fd2b57fb265cf7a79ac70a39b5dedfde1588329c24a
ContainerImageScan (.manager.autoInstrumentationImage.nodejs.repositoryDomain, .manager.autoInstr...
2024-12-03T18:52:31Z INFO [vulndb] Need to update DB 2024-12-03T18:52:31Z INFO [vulndb] Downloading vulnerability DB... 2024-12-03T18:52:31Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2" 2024-12-03T18:52:33Z FATAL Fatal error init error: DB error: failed to download vulnerability DB: OCI artifact error: failed to download vulnerability DB: failed to download artifact from mirror.gcr.io/aquasec/trivy-db:2: oci download error: failed to fetch the layer: GET https://mirror.gcr.io/v2/aquasec/trivy-db/blobs/sha256:091a07a2add2ec3fc0605fd2b57fb265cf7a79ac70a39b5dedfde1588329c24a: BLOB_UNKNOWN: Unknown blob: sha256:091a07a2add2ec3fc0605fd2b57fb265cf7a79ac70a39b5dedfde1588329c24a
ContainerImageScan (.agent.image.repositoryDomainMap.public, .agent.image.repository, .agent.imag...
2024-12-03T18:52:32Z INFO [vulndb] Need to update DB 2024-12-03T18:52:32Z INFO [vulndb] Downloading vulnerability DB... 2024-12-03T18:52:32Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2" 2024-12-03T18:52:34Z FATAL Fatal error init error: DB error: failed to download vulnerability DB: OCI artifact error: failed to download vulnerability DB: failed to download artifact from mirror.gcr.io/aquasec/trivy-db:2: oci download error: failed to fetch the layer: GET https://mirror.gcr.io/v2/aquasec/trivy-db/blobs/sha256:091a07a2add2ec3fc0605fd2b57fb265cf7a79ac70a39b5dedfde1588329c24a: BLOB_UNKNOWN: Unknown blob: sha256:091a07a2add2ec3fc0605fd2b57fb265cf7a79ac70a39b5dedfde1588329c24a
ContainerImageScan (.manager.autoInstrumentationImage.python.repositoryDomain, .manager.autoInstr...
2024-12-03T18:52:33Z INFO [vulndb] Need to update DB 2024-12-03T18:52:33Z INFO [vulndb] Downloading vulnerability DB... 2024-12-03T18:52:33Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2" 2024-12-03T18:52:35Z FATAL Fatal error init error: DB error: failed to download vulnerability DB: OCI artifact error: failed to download vulnerability DB: failed to download artifact from mirror.gcr.io/aquasec/trivy-db:2: oci download error: failed to fetch the layer: GET https://mirror.gcr.io/v2/aquasec/trivy-db/blobs/sha256:091a07a2add2ec3fc0605fd2b57fb265cf7a79ac70a39b5dedfde1588329c24a: BLOB_UNKNOWN: Unknown blob: sha256:091a07a2add2ec3fc0605fd2b57fb265cf7a79ac70a39b5dedfde1588329c24a
ContainerImageScan (.manager.autoInstrumentationImage.dotnet.repositoryDomain, .manager.autoInstr...
CVE-2024-48957 - HIGH severity - libarchive: Out-of-bounds access in libarchive's archive file handling vulnerability in libarchive
ContainerImageScan (.manager.autoInstrumentationImage.dotnet.repositoryDomain, .manager.autoInstr...
CVE-2024-48958 - HIGH severity - libarchive: Out-of-bounds access in libarchive's RAR file handling vulnerability in libarchive
ContainerImageScan (.manager.autoInstrumentationImage.dotnet.repositoryDomain, .manager.autoInstr...
Container image is unhealthy. Following your desired severity threshold (HIGH), the job has been marked as failed.
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-24790 - CRITICAL severity - golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2023-45288 - HIGH severity - golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-34156 - HIGH severity - encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
Container image is unhealthy. Following your desired severity threshold (HIGH), the job has been marked as failed.
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
An error occurred trying to start process '/home/runner/runners/2.321.0/externals/node20/bin/node' with working directory '/home/runner/work/helm-charts/helm-charts'. Argument list too long
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
An error occurred trying to start process '/home/runner/runners/2.321.0/externals/node20/bin/node' with working directory '/home/runner/work/helm-charts/helm-charts'. Argument list too long
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
An error occurred trying to start process '/home/runner/runners/2.321.0/externals/node20/bin/node' with working directory '/home/runner/work/helm-charts/helm-charts'. Argument list too long
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
The template is not valid. System.InvalidOperationException: Maximum object size exceeded at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.ReaderState.CreateState(ReaderState parent, TemplateToken value, TemplateContext context, Int32 removeBytes) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.BasicExpressionState.Next(TemplateToken value, Int32 removeBytes) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.MappingValueBasicExpression() at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.Unravel(Boolean expand) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.AllowScalar(Boolean expand, ScalarToken& scalar) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.Evaluate(DefinitionInfo definition) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.HandleMappingWithAllLooseProperties(DefinitionInfo mappingDefinition, DefinitionInfo keyDefinition, DefinitionInfo valueDefinition, MappingToken mapping) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.Evaluate(DefinitionInfo definition) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.Evaluate(TemplateContext context, String type, TemplateToken template, Int32 removeBytes, Nullable`1 fileId, Boolean omitHeader)
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
The template is not valid. System.InvalidOperationException: Maximum object size exceeded at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.ReaderState.CreateState(ReaderState parent, TemplateToken value, TemplateContext context, Int32 removeBytes) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.BasicExpressionState.Next(TemplateToken value, Int32 removeBytes) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.MappingValueBasicExpression() at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.Unravel(Boolean expand) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.AllowScalar(Boolean expand, ScalarToken& scalar) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.Evaluate(DefinitionInfo definition) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.HandleMappingWithAllLooseProperties(DefinitionInfo mappingDefinition, DefinitionInfo keyDefinition, DefinitionInfo valueDefinition, MappingToken mapping) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.Evaluate(DefinitionInfo definition) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.Evaluate(TemplateContext context, String type, TemplateToken template, Int32 removeBytes, Nullable`1 fileId, Boolean omitHeader)
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2020-16119 - HIGH severity - kernel: DCCP CCID structure use-after-free may lead to DoS or code execution vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2022-36402 - HIGH severity - kernel: vmwgfx: integer overflow in vmwgfx_execbuf.c vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2023-20569 - HIGH severity - amd: Return Address Predictor vulnerability leading to information disclosure vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2023-21400 - HIGH severity - kernel: io_uring: io_defer_entry object double free vulnerability vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-26800 - HIGH severity - kernel: tls: fix use-after-free on failed backlog decryption vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-26960 - HIGH severity - kernel: mm: swap: fix race between free_swap_and_cache() and swapoff() vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-27397 - HIGH severity - kernel: netfilter: nf_tables: use timestamp to check for set element timeout vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-38630 - HIGH severity - kernel: watchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-43882 - HIGH severity - kernel: exec: Fix ToCToU between perm check and set-uid/gid usage vulnerability in linux-libc-dev
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-53103 - HIGH severity - In the Linux kernel, the following vulnerability has been resolved: h ... vulnerability in linux-libc-dev
ContainerImageScan (.manager.autoInstrumentationImage.dotnet.repositoryDomain, .manager.autoInstr...
Dockerfile not provided. Skipping sarif scan result.
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
Dockerfile not provided. Skipping sarif scan result.
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2023-45289 - MEDIUM severity - golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2023-45290 - MEDIUM severity - golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-24783 - MEDIUM severity - golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-24784 - MEDIUM severity - golang: net/mail: comments in display names are incorrectly handled vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-24785 - MEDIUM severity - golang: html/template: errors returned from MarshalJSON methods may break template escaping vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-24789 - MEDIUM severity - golang: archive/zip: Incorrect handling of certain ZIP files vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-24791 - MEDIUM severity - net/http: Denial of service due to improper 100-continue handling in net/http vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-34155 - MEDIUM severity - go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion vulnerability in stdlib
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
CVE-2024-34158 - MEDIUM severity - go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion vulnerability in stdlib
ContainerImageScan (.manager.autoInstrumentationImage.java.repositoryDomain, .manager.autoInstrum...
Dockerfile not provided. Skipping sarif scan result.
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
Encountered an error when evaluating display name ${{ format('echo ''{0}'' ', env.SCAN_RESULT) }}. The template is not valid. System.InvalidOperationException: Maximum object size exceeded at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.ReaderState.CreateState(ReaderState parent, TemplateToken value, TemplateContext context, Int32 removeBytes) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.BasicExpressionState.Next(TemplateToken value, Int32 removeBytes) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.RootBasicExpression() at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.Unravel(Boolean expand) at GitHub.DistributedTask.ObjectTemplating.TemplateUnraveler.AllowScalar(Boolean expand, ScalarToken& scalar) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.Evaluate(DefinitionInfo definition) at GitHub.DistributedTask.ObjectTemplating.TemplateEvaluator.Evaluate(TemplateContext context, String type, TemplateToken template, Int32 removeBytes, Nullable`1 fileId, Boolean omitHeader)
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
Dockerfile not provided. Skipping sarif scan result.
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-10041 - MEDIUM severity - pam: libpam: Libpam vulnerable to read hashed password vulnerability in libpam-modules
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-10963 - MEDIUM severity - pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass vulnerability in libpam-modules
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-10041 - MEDIUM severity - pam: libpam: Libpam vulnerable to read hashed password vulnerability in libpam-modules-bin
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-10963 - MEDIUM severity - pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass vulnerability in libpam-modules-bin
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-10041 - MEDIUM severity - pam: libpam: Libpam vulnerable to read hashed password vulnerability in libpam-runtime
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-10963 - MEDIUM severity - pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass vulnerability in libpam-runtime
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-10041 - MEDIUM severity - pam: libpam: Libpam vulnerable to read hashed password vulnerability in libpam0g
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-10963 - MEDIUM severity - pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass vulnerability in libpam0g
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2024-11168 - MEDIUM severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.8
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2017-13716 - LOW severity - binutils: Memory leak with the C++ symbol demangler routine in libiberty vulnerability in binutils
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2018-20657 - LOW severity - libiberty: Memory leak in demangle_template function resulting in a denial of service vulnerability in binutils
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2019-1010204 - LOW severity - binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service vulnerability in binutils
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2022-48064 - LOW severity - binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwarf2.c vulnerability in binutils
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2017-13716 - LOW severity - binutils: Memory leak with the C++ symbol demangler routine in libiberty vulnerability in binutils-common
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2018-20657 - LOW severity - libiberty: Memory leak in demangle_template function resulting in a denial of service vulnerability in binutils-common
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2019-1010204 - LOW severity - binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service vulnerability in binutils-common
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2022-48064 - LOW severity - binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwarf2.c vulnerability in binutils-common
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2017-13716 - LOW severity - binutils: Memory leak with the C++ symbol demangler routine in libiberty vulnerability in binutils-x86-64-linux-gnu
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
CVE-2018-20657 - LOW severity - libiberty: Memory leak in demangle_template function resulting in a denial of service vulnerability in binutils-x86-64-linux-gnu