Accepted CVEs for Sourcegraph 5.2.4

CVE IDAffected ImagesCVE SeverityCVSS Base ScoreSourcegraph AssessmentCVSS Environmental ScoreDetails
CVE-2023-39325caddy, sourcegraph/executor, sourcegraph/bundled-executorHigh7.5Medium4.7The services that are vulnerable to this issue are typically not exposed on the internet. The likelihood of exploitation is low and this does not have a significant impact on the security of the instance. The issue is not present in Sourcegraph itself.
GHSA-M425-MQ94-257Gcaddy, sourcegraph/executor-kubernetes, sourcegraph/dind, sourcegraph/executor, sourcegraph/bundled-executorHigh7.5Medium5We are not vulnerable to ‘gRPC-Go HTTP/2 Rapid Reset vulnerability’ because we do not expose these service directly to the internet and only reacheable through direct access to the infrastructure.
CVE-2023-5363sourcegraph/dindHigh7.5Info0This workload is not exposed and cannot be reached over the internet. This image is not part of standard deployments.
CVE-2023-47108sourcegraph/dindHigh7.5Info0This workload is not exposed and cannot be reached over the internet. This image is not part of standard deployments.
CVE-2023-45142sourcegraph/dindHigh7.5Info0This workload is not exposed and cannot be reached over the internet. This image is not part of standard deployments.

Known False Positives

Some scanners incorrectly identify false positives in our images:

Vulnerability IDAffected ImagesNote
SNYK-GOLANG-GITHUBCOMCYPHARFILEPATHSECUREJOIN-5889602sourcegraph/cadvisorThis potential security issue only affects filepath-securejoin when used on Windows - all Sourcegraph deployments use Linux