Skip to content

Commit e7e5ce5

Browse files
tatianabgopherbot
authored andcommitted
data/reports: add skip_fix to GO-2022-1180.yaml
Aliases: CVE-2022-47633, GHSA-m3cq-xcx9-3gvm Updates #1180 Change-Id: Ie879d730d352a9329bc7adf36180445bd94846d3 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466078 Run-TryBot: Tatiana Bradley <[email protected]> Reviewed-by: Tim King <[email protected]> TryBot-Result: Gopher Robot <[email protected]> Auto-Submit: Tatiana Bradley <[email protected]>
1 parent 5de5ceb commit e7e5ce5

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

data/reports/GO-2022-1180.yaml

+2-1
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ modules:
33
versions:
44
- introduced: 1.8.3
55
fixed: 1.8.5
6-
vulnerable_at: 1.8.4
6+
vulnerable_at: 1.8.5-0.20221217180442-ef63302dc479
77
packages:
88
- package: github.com/kyverno/kyverno/pkg/engine
99
symbols:
@@ -12,6 +12,7 @@ modules:
1212
- imageVerifier.verifyAttestors
1313
- imageVerifier.verifyAttestorSet
1414
- imageVerifier.verifyImage
15+
skip_fix: 'TODO: revisit this reason (undefined: gojmespath.NotFoundError)'
1516
description: |
1617
`verifyImages` rules can be bypassed by a malicious proxy/registry.
1718
cves:

0 commit comments

Comments
 (0)