Accepted CVEs for Sourcegraph 5.2.3

CVE IDAffected ImagesCVE SeverityCVSS Base ScoreSourcegraph AssessmentCVSS Environmental ScoreDetails
CVE-2023-39325caddyHigh7.5Medium4.7The services that are vulnerable to this issue are typically not exposed on the internet. The likelihood of exploitation is low and this does not have a significant impact on the security of the instance. The issue is not present in Sourcegraph itself.
CVE-2023-39325caddy, sourcegraph/executor, sourcegraph/bundled-executorHigh7.5Medium4.7The services that are vulnerable to this issue are typically not exposed on the internet. The likelihood of exploitation is low and this does not have a significant impact on the security of the instance. The issue is not present in Sourcegraph itself.
GHSA-M425-MQ94-257Gcaddy, sourcegraph/executor-kubernetes, sourcegraph/dind, sourcegraph/executor, sourcegraph/bundled-executorHigh7.5Medium5We are not vulnerable to ‘gRPC-Go HTTP/2 Rapid Reset vulnerability’ because we do not expose these service directly to the internet and only reacheable through direct access to the infrastructure.

Known False Positives

Some scanners incorrectly identify false positives in our images:

Vulnerability IDAffected ImagesNote
SNYK-GOLANG-GITHUBCOMCYPHARFILEPATHSECUREJOIN-5889602sourcegraph/cadvisorThis potential security issue only affects filepath-securejoin when used on Windows - all Sourcegraph deployments use Linux