cve: synapse carries six of its own, and they were nearly missed

The pipeline still holds the report for v1.151, so the six criticals in v1.158
never showed up in any query against it. They surfaced only from re-deriving the
target set against the live cluster and folding in the pre-deploy scans by hand.
Five sit without a fix in the debian base, one in the bundled tool's go runtime;
the chart sets the version, so there is nothing to take.

With that entry the count over all 54 desired targets is zero open.
This commit is contained in:
Thore Cimbal
2026-08-21 12:00:00 +00:00
parent d5e2995314
commit 422b651f43
+14
View File
@@ -104,6 +104,20 @@
"GHSA-r277-6w6q-xmqw"
]
},
{
"ziel": "oci.element.io/synapse:v1.158.0",
"art": "hingenommen",
"grund": "Fassung vom ESS-Chart 26.8.0 gesetzt und heute erst gehoben (v1.151.0-ess.1 -> v1.158.0, 11 CRITICAL -> 6). Fuenf der sechs sitzen ohne Fix-Fassung in libxml2 und perl-base der Debian-Basis; der sechste ist die Go-stdlib des mitgelieferten Werkzeugs. Ein eigenes Image zu bauen, nur um diese Basis zu tauschen, waere unverhaeltnismaessig - der naechste ESS-Sprung bringt sie mit.",
"pruefen_am": "2026-09-21",
"cves": [
"CVE-2025-68121",
"CVE-2026-13221",
"CVE-2026-42496",
"CVE-2026-57433",
"CVE-2026-6653",
"CVE-2026-8376"
]
},
{
"ziel": "portainer/agent:2.27.5",
"art": "geplant",