Accepted CVEs for Sourcegraph 5.3.2

CVE IDAffected ImagesCVE SeverityCVSS Base ScoreSourcegraph AssessmentCVSS Environmental ScoreDetails
CVE-2023-39325sourcegraph/dindHigh7.5Medium4.7The services that are vulnerable to this issue are typically not exposed on the internet. The likelihood of exploitation is low and this does not have a significant impact on the security of the instance. The issue is not present in Sourcegraph itself.
GHSA-M425-MQ94-257Gsourcegraph/dind, sourcegraph/executor, sourcegraph/bundled-executor, sourcegraph/executor, sourcegraph/bundled-executor, sourcegraph/dind, caddy, sourcegraph/executor-kubernetesHigh7.5Medium4.7The services that are vulnerable to this issue are typically not exposed on the internet. The likelihood of exploitation is low and this does not have a significant impact on the security of the instance. The issue is not present in Sourcegraph itself.
CVE-2023-47108sourcegraph/dindHigh7.5Info0This workload is not exposed and cannot be reached over the internet. This image is not part of standard deployments.
CVE-2023-45142sourcegraph/dindHigh7.5Info0This workload is not exposed and cannot be reached over the internet. This image is not part of standard deployments.
CVE-2023-7104sourcegraph/codeinsights-db, sourcegraph/codeintel-db, sourcegraph/postgres-12-alpineHigh7.3Medium4.1This is not exploitable over the internet. It would require an actor to write very specific SQLITE queries which is not possible in the default configuration.
CVE-2024-23652sourcegraph/dindCritical7.4Info0We are not vulnerable for this issue as it requires access to our underlying infrastructure for exploitation. An actor cannot use this to gain access to our instances.
CVE-2024-23653sourcegraph/dindCritical9.8Info0We are not vulnerable for this issue as it requires access to our underlying infrastructure for exploitation. An actor cannot use this to gain access to our instances.
CVE-2024-23651sourcegraph/dindHigh7.4Info0We are not vulnerable for this issue as it requires access to our underlying infrastructure for exploitation. An actor cannot use this to gain access to our instances.
CVE-2024-21626sourcegraph/dindHigh8.6High8.6Dind is used for Kubernetes executors and is not part of the standard deployment. This issue is not fixed in the latest dind release, and we will upgrade once a patch is available.
CVE-2023-5363sourcegraph/dindHigh0info0This workload is not exposed and cannot be reached over the internet. This image is not part of standard deployments.