File tree Expand file tree Collapse file tree 1 file changed +9
-0
lines changed Expand file tree Collapse file tree 1 file changed +9
-0
lines changed Original file line number Diff line number Diff line change @@ -33,6 +33,15 @@ provenance:
3333 slsa : true
3434sbom :
3535 enabled : true
36+ ignoreVulnerabilities :
37+ - vulnerability : CVE-2022-33171
38+ reason : |
39+ This vulnerability in TypeORM's findOne / findOneOrFail functions can improperly interpret a crafted JSON object
40+ and concatenate it into raw SQL, potentially allowing SQL injection attacks.
41+
42+ In Gitpod’s usage, TypeORM is not exposed to arbitrary user input. For example, DB migrations run preset queries;
43+ the server/bridge code does not hand raw JSON from external sources to findOne. Therefore, there is no path for
44+ injecting malicious JSON into a query, rendering the vulnerability non-exploitable.
3645environmentManifest :
3746 - name : " go"
3847 command : ["sh", "-c", "go version | sed s/arm/amd/"]
You can’t perform that action at this time.
0 commit comments