Accepted CVEs for Sourcegraph 5.2.2

CVE IDAffected ImagesCVE SeverityCVSS Base ScoreSourcegraph AssessmentCVSS Environmental ScoreDetails
CVE-2023-45142High7.5Medium5.7There is currently no patched version for Caddy available that resolves this issue. We will update once the patch is available. The instances are not typically exposed on the internet thus the likelihood of exploitation is low. This issue only has a potential impact on the availability of the Caddy service.
CVE-2023-45853sourcegraph/github-proxyCritical9.8Medium4.7This vulnerability impacts zlib library used for managing zip files. This issue is not present in Sourcegraph as the application doesn’t accept zip files as part of the request.
CVE-2023-39325High7.5Medium4.7The services that are vulnerable to this issue are typically not exposed on the internet. The likelihood of exploitation is low and this does not have a significant impact on the security of the instance. The issue is not present in Sourcegraph itself.
CVE-2023-45142sourcegraph/dindHigh7.5Medium4.0We are not vulnerable for ‘DoS vulnerability in otelhttp’ because sourcegraph/dind is not exposed to attackers and only reacheable through direct access to the infrastructure.
CVE-2023-39325caddy, sourcegraph/executor-kubernetes, sourcegraph/dind, sourcegraph/executor, sourcegraph/bundled-executorHigh7.5Medium4.7The services that are vulnerable to this issue are typically not exposed on the internet. The likelihood of exploitation is low and this does not have a significant impact on the security of the instance. The issue is not present in Sourcegraph itself.
GHSA-M425-MQ94-257Gcaddy, sourcegraph/executor-kubernetes, sourcegraph/dind, sourcegraph/executor, sourcegraph/bundled-executorHighNVD had no metrics available at this timeWe are not vulnerable to ‘gRPC-Go HTTP/2 Rapid Reset vulnerability’ because we do not expose these service directly to the internet and only reacheable through direct access to the infrastructure.

Known False Positives

Some scanners incorrectly identify false positives in our images:

Vulnerability IDAffected ImagesNote
SNYK-GOLANG-GITHUBCOMCYPHARFILEPATHSECUREJOIN-5889602sourcegraph/cadvisorThis potential security issue only affects filepath-securejoin when used on Windows - all Sourcegraph deployments use Linux