Skip to content

Commit

Permalink
Merge pull request #21020 from felipecruz91/cups-cves
Browse files Browse the repository at this point in the history
chore(scout): Document CUPS CVEs in high-profile vuln policy
  • Loading branch information
dvdksn authored Sep 30, 2024
2 parents 365dac4 + d355d22 commit 82acbd8
Showing 1 changed file with 6 additions and 2 deletions.
8 changes: 6 additions & 2 deletions content/manuals/scout/policy/_index.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,13 +145,17 @@ The list includes the following vulnerabilities:
- [CVE-2023-38545 (cURL SOCKS5 heap buffer overflow)](https://scout.docker.com/v/CVE-2023-38545)
- [CVE-2023-44487 (HTTP/2 Rapid Reset)](https://scout.docker.com/v/CVE-2023-44487)
- [CVE-2024-3094 (XZ backdoor)](https://scout.docker.com/v/CVE-2024-3094)
- [CVE-2024-47176 (OpenPrinting - cups-browsed)](https://scout.docker.com/v/CVE-2024-47176)
- [CVE-2024-47076 (OpenPrinting - libcupsfilters)](https://scout.docker.com/v/CVE-2024-47076)
- [CVE-2024-47175 (OpenPrinting- libppd)](https://scout.docker.com/v/CVE-2024-47175)
- [CVE-2024-47177 (OpenPrinting - cups-filters)](https://scout.docker.com/v/CVE-2024-47177)

You can configure the CVEs included in this list by creating a custom policy.
Custom configuration options include:

- **CVEs to avoid**: Specify the CVEs that you want to avoid in your artifacts.
- **Excluded CVEs**: Specify the CVEs that you want this policy to ignore.

Default: `CVE-2014-0160`, `CVE-2021-44228`, `CVE-2023-38545`, `CVE-2023-44487`, `CVE-2024-3094`
Default: `[]` (none of the high-profile CVEs are ignored)

- **CISA KEV**: Enable tracking of vulnerabilities from CISA's Known Exploited Vulnerabilities (KEV) catalog

Expand Down

0 comments on commit 82acbd8

Please sign in to comment.