Accepted CVEs for Sourcegraph 5.2.0

CVE IDAffected ImagesCVE SeverityCVSS Base ScoreSourcegraph AssessmentCVSS Environmental ScoreDetails

No known CVEs in Sourcegraph 5.2.0

Known False Positives

Some scanners incorrectly identify false positives in our images:

Vulnerability IDAffected ImagesNote
SNYK-GOLANG-GITHUBCOMCYPHARFILEPATHSECUREJOIN-5889602sourcegraph/cadvisorThis potential security issue only affects filepath-securejoin when used on Windows - all Sourcegraph deployments use Linux