Accepted CVEs for Sourcegraph 5.1.5

CVE IDAffected ImagesCVE SeverityCVSS Base ScoreSourcegraph AssessmentCVSS Environmental ScoreDetails
CVE-2022-27191caddyHigh7.5Info0This image is only used in docker deployments. This vulnerability impacts SSH servers using the affected dependency. Caddy does not have ssh servers, much less using the dependency. Sourcegraph is not affected by this issue.
CVE-2022-27664caddyHigh7.5Low1.7This image is only used in docker deployments. This is a denial of service vulnerability that could affect the availability of Sourcegraph services in specific situations. As Sourcegraph is run as an internal service, our assessment of the severity of this issue is Low.
CVE-2022-41723caddyHigh7.5Low2.1This image is only used in docker deployments. This is a denial of service vulnerability that could affect the availability of Sourcegraph services in specific situations. This vulnerability can only affect via internal traffic within our application, not external access or unauthenticated user, and limited to the site-admin vector. Our assessment of the severity of this issue is Low.
CVE-2022-32149caddyHigh7.5Medium5.7This image is only used in docker deployments. It could only potentially be used to cause a denial of service from an attacker in a privileged network position. It will be fixed in the next Sourcegraph release.
CVE-2022-4450caddyHigh7.5Info0This image is only used in docker deployments. Caddy does not process PEM files and cannot be exploited by this issue.
CVE-2023-0215caddyHigh7.5Info0This image is only used in docker deployments. Caddy does not use SMIME, CMS and PKCS7 streaming capabilities and cannot be exploited by this issue.
CVE-2023-0286caddyHigh7.4Info0This image is only used in docker deployments. Caddy does not process X.400 addresses and cannot be exploited by this issue.
CVE-2023-0464caddyHigh7.5Info0This image is only used in docker deployments. Caddy does verify X.509 certificates and cannot be exploited by this issue.
CVE-2023-2650caddyHigh7.5Info0.0This image is only used in docker deployments. This issue only affects servers that allow client authentication using X.509 certificates, which our Caddy deployment does not.

Known False Positives

Some scanners incorrectly identify false positives in our images:

Vulnerability IDAffected ImagesNote
CVE-2023-27561sourcegraph/cadvisorFalse positive - this is patched in github.com/opencontainers/runc/libcontainer@v1.1.5
CVE-2022-0543, CVE-2022-3734sourcegraph/redis-cache, sourcegraph/redis-store, sourcegraph/serverFalse positive - these vulnerabilities are specific to Windows and Debian releases
CVE-2022-31107, CVE-2022-31123, CVE-2022-31130, CVE-2022-39201sourcegraph/grafana, sourcegraph/serverFalse positive - these vulnerabilities have been patched by Chainguard