View Code? Open in Web Editor
NEW
This project forked from google /cadvisor
Analyzes resource usage and performance characteristics of running containers.
License: Other
Go 94.06%
Shell 1.56%
Makefile 0.22%
Python 0.44%
JavaScript 2.79%
HTML 0.78%
Dockerfile 0.16%
cadvisor's People
Watchers
cadvisor's Issues
CVE-2020-11022 - Medium Severity Vulnerability
Vulnerable Libraries - github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/container/docker-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/container-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
❌ github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/container/docker-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/container-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/integration/framework-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
❌ github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/utils/cpuload-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/utils/cpuload/netlink-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
Found in HEAD commit: e4fb7b2d48835a6901c7b2e4a1bc7d1a57cab6b9
Vulnerability Details
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Publish Date: 2020-04-29
URL: CVE-2020-11022
CVSS 3 Score Details (6.1 )
Base Score Metrics:
Exploitability Metrics:
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: Required
Scope: Changed
Impact Metrics:
Confidentiality Impact: Low
Integrity Impact: Low
Availability Impact: None
For more information on CVSS3 Scores, click here .
Suggested Fix
Type: Upgrade version
Origin: https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
Release Date: 2020-04-29
Fix Resolution: jQuery - 3.5.0
CVE-2019-8331 - Medium Severity Vulnerability
Vulnerable Libraries - github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec , bootstrap-4.0.0-beta.2.min.js , github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/container/docker-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/container-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
❌ github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
bootstrap-4.0.0-beta.2.min.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.0.0-beta.2/js/bootstrap.min.js
Path to vulnerable library: /cadvisor/cmd/internal/pages/assets/js/bootstrap-4.0.0-beta.2.min.js
Dependency Hierarchy:
❌ bootstrap-4.0.0-beta.2.min.js (Vulnerable Library)
github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/container/docker-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/container-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/integration/framework-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
❌ github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/utils/cpuload-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/utils/cpuload/netlink-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
Found in HEAD commit: e4fb7b2d48835a6901c7b2e4a1bc7d1a57cab6b9
Vulnerability Details
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Publish Date: 2019-02-20
URL: CVE-2019-8331
CVSS 3 Score Details (6.1 )
Base Score Metrics:
Exploitability Metrics:
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: Required
Scope: Changed
Impact Metrics:
Confidentiality Impact: Low
Integrity Impact: Low
Availability Impact: None
For more information on CVSS3 Scores, click here .
Suggested Fix
Type: Upgrade version
Origin: twbs/bootstrap#28236
Release Date: 2019-02-20
Fix Resolution: bootstrap - 3.4.1,4.3.1;bootstrap-sass - 3.4.1,4.3.1
CVE-2019-11358 - Medium Severity Vulnerability
Vulnerable Libraries - github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec , github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/stats-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/container/docker-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/container-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/container/crio-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
❌ github.com/google/cadvisor/perf-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/manager-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/container/docker-33463ad2210c2490c2cfe822113ffe364d079eec
github.com/google/cadvisor/container-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/container/containerd-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/integration/framework-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
❌ github.com/google/cadvisor/client/v2-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec
Analyzes resource usage and performance characteristics of running containers.
Dependency Hierarchy:
github.com/google/cadvisor/utils/cpuload-33463ad2210c2490c2cfe822113ffe364d079eec (Root Library)
github.com/google/cadvisor/utils/cpuload/netlink-33463ad2210c2490c2cfe822113ffe364d079eec
❌ github.com/google/cadvisor/info/v1-33463ad2210c2490c2cfe822113ffe364d079eec (Vulnerable Library)
Found in HEAD commit: e4fb7b2d48835a6901c7b2e4a1bc7d1a57cab6b9
Vulnerability Details
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native Object.prototype.
Publish Date: 2019-04-20
URL: CVE-2019-11358
CVSS 3 Score Details (6.1 )
Base Score Metrics:
Exploitability Metrics:
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: Required
Scope: Changed
Impact Metrics:
Confidentiality Impact: Low
Integrity Impact: Low
Availability Impact: None
For more information on CVSS3 Scores, click here .
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11358
Release Date: 2019-04-20
Fix Resolution: 3.4.0