1"use strict";(self.webpackChunkpartners=self.webpackChunkpartners||[]).push([[32727],{15680:(e,t,n)=>{n.d(t,{xA:()=>p,yg:()=>v});var i=n(96540);function l(e,t,n){return t in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function o(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var i=Object.getOwnPropertySymbols(e);t&&(i=i.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),n.push.apply(n,i)}return n}function a(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?o(Object(n),!0).forEach((function(t){l(e,t,n[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):o(Object(n)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))}))}return e}function s(e,t){if(null==e)return{};var n,i,l=function(e,t){if(null==e)return{};var n,i,l={},o=Object.keys(e);for(i=0;i<o.length;i++)n=o[i],t.indexOf(n)>=0||(l[n]=e[n]);return l}(e,t);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);for(i=0;i<o.length;i++)n=o[i],t.indexOf(n)>=0||Object.prototype.propertyIsEnumerable.call(e,n)&&(l[n]=e[n])}return l}var r=i.createContext({}),u=function(e){var t=i.useContext(r),n=t;return e&&(n="function"==typeof e?e(t):a(a({},t),e)),n},p=function(e){var t=u(e.components);return i.createElement(r.Provider,{value:t},e.children)},c="mdxType",d={inlineCode:"code",wrapper:function(e){var t=e.children;return i.createElement(i.Fragment,{},t)}},g=i.forwardRef((function(e,t){var n=e.components,l=e.mdxType,o=e.originalType,r=e.parentName,p=s(e,["components","mdxType","originalType","parentName"]),c=u(n),g=l,v=c["".concat(r,".").concat(g)]||c[g]||d[g]||o;return n?i.createElement(v,a(a({ref:t},p),{},{components:n})):i.createElement(v,a({ref:t},p))}));function v(e,t){var n=arguments,l=t&&t.mdxType;if("string"==typeof e||l){var o=n.length,a=new Array(o);a[0]=g;var s={};for(var r in t)hasOwnProperty.call(t,r)&&(s[r]=t[r]);s.originalType=e,s[c]="string"==typeof e?e:l,a[1]=s;for(var u=2;u<o;u++)a[u]=n[u];return i.createElement.apply(null,a)}return i.createElement.apply(null,n)}g.displayName="MDXCreateElement"},68798:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>r,contentTitle:()=>a,default:()=>d,frontMatter:()=>o,metadata:()=>s,toc:()=>u});var i=n(58168),l=(n(96540),n(15680));const o={title:"Security audit report"},a=void 0,s={unversionedId:"docs/on-premises/security-audit-report",id:"docs/on-premises/security-audit-report",title:"Security audit report",description:"Vulnerability scanning",source:"@site/docs/docs/on-premises/security-audit-report.md",
1sourceDirName:"docs/on-premises",slug:"/docs/on-premises/security-audit-report",permalink:"/docs/on-premises/security-audit-report",draft:!1,editUrl:"https://github.com/pactflow/docs.pactflow.io/edit/master/website/docs/docs/on-premises/security-audit-report.md",tags:[],version:"current",lastUpdatedBy:"Matt Fellows",lastUpdatedAt:1752199668,formattedLastUpdatedAt:"Jul 11, 2025",frontMatter:{title:"Security audit report"},sidebar:"onprem",previous:{title:"On-Premises SCIM API",permalink:"/docs/on-premises/scim"},next:{title:"Support policy",permalink:"/docs/on-premises/support-policy"}},r={},u=[{value:"Vulnerability scanning",id:"vulnerability-scanning",level:2},{value:"Reporting vulnerabilities",id:"reporting-vulnerabilities",level:2},{value:"Identifying the correct Ruby version",id:"identifying-the-correct-ruby-version",level:2},{value:"Identifying the installed gem versions",id:"identifying-the-installed-gem-versions",level:2},{value:"Known advisories",id:"known-advisories",level:2},{value:"CVE-2015-9284",id:"cve-2015-9284",level:3},{value:"Component",id:"component",level:4},{value:"CVE",id:"cve",level:4},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow",level:4},{value:"Status",id:"status",level:4},{value:"Notes",id:"notes",level:4},{value:"CVE-2022-2625",id:"cve-2022-2625",level:3},{value:"Description",id:"description",level:4},{value:"Component",id:"component-1",level:4},{value:"CVE",id:"cve-1",level:4},{value:"Status",id:"status-1",level:4},{value:"Notes",id:"notes-1",level:4},{value:"CVE-2022-37434",id:"cve-2022-37434",level:3},{value:"Description",id:"description-1",level:4},{value:"Component",id:"component-2",level:4},{value:"CVE",id:"cve-2",level:4},{value:"Affected versions of PactFlow",id:"affected-versions-of-pactflow",level:4},{value:"Status",id:"status-2",level:4},{value:"Notes",id:"notes-2",level:4},{value:"CVE-2021-41816",id:"cve-2021-41816",level:3},{value:"Component",id:"component-3",level:4},{value:"CVE",id:"cve-3",level:4},{value:"Status",id:"status-3",level:4},{value:"Notes",id:"notes-3",level:4},{value:"CVE-2020-36599",id:"cve-2020-36599",level:3},{value:"Description",id:"description-2",level:4},{value:"Component",id:"component-4",level:4},{value:"Status",id:"status-4",level:4},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow-1",level:4},{value:"Fixed versions",id:"fixed-versions",level:4},{value:"Notes",id:"notes-4",level:4},{value:"CVE-2025-22872",id:"cve-2025-22872",level:3},{value:"Description",id:"description-3",level:4},{value:"CVE",id:"cve-4",level:4},{value:"Component",id:"component-5",level:4},{value:"Status",id:"status-5",level:4},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow-2",level:4},{value:"Fixed versions",id:"fixed-versions-1",level:4},{value:"Notes",id:"notes-5",level:4},{value:"CVE-2025-22874",id:"cve-2025-22874",level:3},{value:"Description",id:"description-4",level:4},{value:"CVE",id:"cve-5",level:4},{value:"Component",id:"component-6",level:4},{value:"Status",id:"status-6",level:4},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow-3",level:4},{value:"Fixed versions",id:"fixed-versions-2",level:4},{value:"Notes",id:"notes-6",level:4}],p={toc:u},c="wrapper";function d(e){let{components:t,...n}=e;return(0,l.yg)(c,(0,i.A)({},p,n,{components:t,mdxType:"MDXLayout"}),(0,l.yg)("h2",{id:"vulnerability-scanning"},"Vulnerability scanning"),(0,l.yg)("p",null,"PactFlow uses the following tools to ensure the On-Premises image is kept as secure as possible."),(0,l.yg)("ul",null,(0,l.yg)("li",{parentName:"ul"},"Bundler Audit"),(0,l.yg)("li",{parentName:"ul"},"NPM audit"),(0,l.yg)("li",{parentName:"ul"},"Trivy"),(0,l.yg)("li",{parentName:"ul"},"Quay Security Scanner"),(0,l.yg)("li",{parentName:"ul"},"Amazon ECR Image scanning")),(0,l.yg)("h2",{id:"reporting-vulnerabilities"},"Reporting vulnerabilities"),(0,l.yg)("p",null,"To report a vulnerability, please ",(0,l.yg)("a",{parentName:"p",href:"https://smartbear.com/security/"},"contact security")," and ensure you include the relevant CVE, and the name and/or path to the vulnerable component."),(0,l.yg)("h2",{id:"identifying-the-correct-ruby-version"},"Identifying the correct Ruby version"),(0,l.yg)("p",null,"Many scanning tools have trouble identifying the correct version of Ruby installed on an image because Ruby stores its gems in a directory path that uses the minor version of Ruby (eg. ",(0,l.yg)("inlineCode",{parentName:"p"},"2.7.0"),") rather than the patch version (eg. ",(0,l.yg)("inlineCode",{parentName:"p"},"2.7.6"),"). This can be demonstrated by running the following command:"),(0,l.yg)("pre",null,(0,l.yg)("c
1ode",{parentName:"pre",className:"language-shell"},"docker run --rm -it --entrypoint gem quay.io/pactflow/enterprise:latest environment\n")),(0,l.yg)("p",null,"Example output (note the ",(0,l.yg)("inlineCode",{parentName:"p"},"RUBY VERSION")," of ",(0,l.yg)("inlineCode",{parentName:"p"},"2.7.6")," while the ",(0,l.yg)("inlineCode",{parentName:"p"},"GEM PATHS")," use ",(0,l.yg)("inlineCode",{parentName:"p"},"2.7.0"),"):"),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre",className:"language-shell"},'RubyGems Environment:\n - RUBYGEMS VERSION: 3.1.6\n - RUBY VERSION: 2.7.6 (2022-04-12 patchlevel 219) [x86_64-linux-musl]\n - INSTALLATION DIRECTORY: /usr/local/bundle\n - USER INSTALLATION DIRECTORY: /root/.gem/ruby/2.7.0\n - RUBY EXECUTABLE: /usr/local/bin/ruby\n - GIT EXECUTABLE:\n - EXECUTABLE DIRECTORY: /usr/local/bundle/bin\n - SPEC CACHE DIRECTORY: /root/.gem/specs\n - SYSTEM CONFIGURATION DIRECTORY: /usr/local/etc\n - RUBYGEMS PLATFORMS:\n - ruby\n - x86_64-linux-musl\n - GEM PATHS:\n - /usr/local/bundle\n - /root/.gem/ruby/2.7.0\n - /usr/local/lib/ruby/gems/2.7.0\n - GEM CONFIGURATION:\n - :update_sources => true\n - :verbose => true\n - :backtrace => false\n - :bulk_threshold => 1000\n - "install" => "--no-document"\n - "update" => "--no-document"\n - REMOTE SOURCES:\n - https://rubygems.org/\n - SHELL PATH:\n - /usr/local/bundle/bin\n - /usr/local/sbin\n - /usr/local/bin\n - /usr/sbin\n - /usr/bin\n - /sbin\n - /bin\n')),(0,l.yg)("p",null,"The difficulty that tools have in identifying the correct version of Ruby can lead to false positives being reported. Please check the version of Ruby before submitting a vulnerability report."),(0,l.yg)("h2",{id:"identifying-the-installed-gem-versions"},"Identifying the installed gem versions"),(0,l.yg)("p",null,"To list the gems installed on the PactFlow image run:"),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre"},'docker run --rm -it --entrypoint gem quay.io/pactflow/enterprise:latest "list"\n')),(0,l.yg)("h2",{id:"known-advisories"},"Known advisories"),(0,l.yg)("h3",{id:"cve-2015-9284"},"CVE-2015-9284"),(0,l.yg)("h4",{id:"component"},"Component"),(0,l.yg)("p",null,"omniauth gem"),(0,l.yg)("h4",{id:"cve"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2015-9284"},"https://nvd.nist.gov/vuln/detail/CVE-2015-9284")),(0,l.yg)("h4",{id:"detectable-in-versions-of-pactflow"},"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"All."),(0,l.yg)("h4",{id:"status"},"Status"),(0,l.yg)("p",null,"Non-exploitable."),(0,l.yg)("h4",{id:"notes"},"Notes"),(0,l.yg)("p",null,"This CVE is a CSRF vulnerability during sign in. This vulnerability is only exploitable if the initial request from the service provider to the identify provider is vulnerable to a CSRF attack because it uses a GET request without any CSRF protection. In PactFlow, this is not possible as PactFlow uses a POST request method with a CSRF token for the initial request to the IDP, as per the mitigation instructions ",(0,l.yg)("a",{parentName:"p",href:"https://github.com/omniauth/omniauth/wiki/Resolving-CVE-2015-9284"},"here"),"."),(0,l.yg)("p",null,"This can be observed by viewing the source of the login form."),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre",className:"language-html"},'<form action="https://example.com/auth/saml" method="post">\n <input type="hidden" name="authenticity_token" value="i_nnrcJziCKKNMb-FRQtxot2ZE6nsNpIhC_AtsK5Boc=">\n <button type="submit">SAML</button>\n</form>\n')),(0,l.yg)("h3",{id:"cve-2022-2625"},"CVE-2022-2625"),(0,l.yg)("h4",{id:"description"},"Description"),(0,l.yg)("p",null,"Given certain prerequisites, this vulnerability allows arbitrary code to be run."),(0,l.yg)("h4",{id:"component-1"},"Component"),(0,l.yg)("p",null,"postgresql14-dev package for Alpine"),(0,l.yg)("h4",{id:"cve-1"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2022-2625"},"https://nvd.nist.gov/vuln/detail/CVE-2022-2625")),(0,l.yg)("h4",{id:"status-1"},"Status"),(0,l.yg)("p",null,"Non-exploitable."),(0,l.yg)("h4",{id:"notes-1"},"Notes"),(0,l.yg)("p",null,"This vulnerability applies to the PostgreSQL server only. The PactFlow Docker image only uses the PostgreSQL client, and hence is not affected by this vulnerability."),(0,l.yg)("h3",{id:"cve-2022-37434"},"CVE-2022-37434"),(0,l.yg)("h4",{id:"description-1"},"Description"),(0,l.yg)("p",null,"A heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field."),(0,l.yg)("h4",{id:"component-2"},"Component"),(0,l.yg)("p",null,"zlib package for Alpine"),(0,l.yg)("h4",{id:"cve-2"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2022-37434"},"https://nvd.nist.gov/vuln/detail/CVE-2022-37434")),(0,l.yg)("h4",{id:"affected-versions-of-pactflow"},"Affected versions of PactFlow"),(0,l.yg)("p",null,"All."),(0,l.yg)("h4",{id:"status-2"},"Status"),(0,l.yg)("p",null,"Unfixed."),(0,l.yg)("h4",{id:"notes-2"},"Notes"),(0,l.yg)("p",null,"As of 24 August 2022, there is no fix available. A patch release of PactFlow will be put out as soon as a fix is available."),(0,l.yg)("h3",{id:"cve-2021-41816"}
1,"CVE-2021-41816"),(0,l.yg)("h4",{id:"component-3"},"Component"),(0,l.yg)("p",null,"The cgi library included in Ruby before 2.7.5 and 3.x before 3.0.3, and the ",(0,l.yg)("a",{parentName:"p",href:"https://rubygems.org/gems/cgi"},"cgi gem")," before 0.3.1."),(0,l.yg)("h4",{id:"cve-3"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2021-41816"},"https://nvd.nist.gov/vuln/detail/CVE-2021-41816")),(0,l.yg)("h4",{id:"status-3"},"Status"),(0,l.yg)("p",null,"False positive."),(0,l.yg)("h4",{id:"notes-3"},"Notes"),(0,l.yg)("p",null,"This vulnerability only affects platforms that use a 4 byte long data type, typically Windows. The PactFlow base image uses 64 bit Alpine Linux, which uses an ",(0,l.yg)("a",{parentName:"p",href:"https://www.ibm.com/docs/en/ibm-mq/9.0?topic=platforms-standard-data-types-unix-linux-windows"},"8 byte long"),"."),(0,l.yg)("h3",{id:"cve-2020-36599"},"CVE-2020-36599"),(0,l.yg)("h4",{id:"description-2"},"Description"),(0,l.yg)("p",null,"lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value."),(0,l.yg)("h4",{id:"component-4"},"Component"),(0,l.yg)("p",null,"omniauth gem"),(0,l.yg)("h4",{id:"status-4"},"Status"),(0,l.yg)("p",null,"Non-exploitable."),(0,l.yg)("h4",{id:"detectable-in-versions-of-pactflow-1"},"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"Up to and including 1.19.2."),(0,l.yg)("h4",{id:"fixed-versions"},"Fixed versions"),(0,l.yg)("p",null,"1.19.3 and later."),(0,l.yg)("h4",{id:"notes-4"},"Notes"),(0,l.yg)("p",null,"PactFlow uses a custom failure endpoint so the vulnerable code is never executed."),(0,l.yg)("h3",{id:"cve-2025-22872"},"CVE-2025-22872"),(0,l.yg)("h4",{id:"description-3"},"Description"),(0,l.yg)("p",null,"The ",(0,l.yg)("a",{parentName:"p",href:"https://pkg.go.dev/golang.org/x/net"},"https://pkg.go.dev/golang.org/x/net")," package tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. ",(0,l.yg)("inlineCode",{parentName:"p"},"<math>"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"<svg>"),", etc contexts)."),(0,l.yg)("h4",{id:"cve-4"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2025-22872"},"https://nvd.nist.gov/vuln/detail/CVE-2025-22872")),(0,l.yg)("h4",{id:"component-5"},"Component"),(0,l.yg)("p",null,(0,l.yg)("inlineCode",{parentName:"p"},"dockerize")," (a command-line utility available to use as a helpful entrypoint when starting PactFlow)."),(0,l.yg)("h4",{id:"status-5"},"Status"),(0,l.yg)("p",null,"Non-exploitable."),(0,l.yg)("h4",{id:"detectable-in-versions-of-pactflow-2"},"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"Up to and including 1.37.0."),(0,l.yg)("h4",{id:"fixed-versions-1"},"Fixed versions"),(0,l.yg)("p",null,"n/a"),(0,l.yg)("h4",{id:"notes-5"},"Notes"),(0,l.yg)("p",null,(0,l.yg)("inlineCode",{parentName:"p"},"dockerize")," is not, and cannot, be used in a web-based context where the XSS threat is present. "),(0,l.yg)("h3",{id:"cve-2025-22874"},"CVE-2025-22874"),(0,l.yg)("h4",{id:"description-4"},"Description"),(0,l.yg)("p",null,"Calling ",(0,l.yg)("inlineCode",{parentName:"p"},"Verify")," with a ",(0,l.yg)("inlineCode",{parentName:"p"},"VerifyOptions.KeyUsages")," that contains ",(0,l.yg)("inlineCode",{parentName:"p"},"ExtKeyUsageAny")," unintentionally disabled policy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon."),(0,l.yg)("h4",{id:"cve-5"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2025-22872"},"https://nvd.nist.gov/vuln/detail/CVE-2025-22872")),(0,l.yg)("h4",{id:"component-6"},"Component"),(0,l.yg)("p",null,(0,l.yg)("inlineCode",{parentName:"p"},"dockerize")," (a command-line utility available to use as a helpful entrypoint when starting PactFlow)."),(0,l.yg)("h4",{id:"status-6"},"Status"),(0,l.yg)("p",null,"Non-exploitable."),(0,l.yg)("h4",{id:"detectable-in-versions-of-pactflow-3"}
1,"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"Up to and including 1.37.0."),(0,l.yg)("h4",{id:"fixed-versions-2"},"Fixed versions"),(0,l.yg)("p",null,"n/a"),(0,l.yg)("h4",{id:"notes-6"},"Notes"),(0,l.yg)("p",null,"The primary use of ",(0,l.yg)("inlineCode",{parentName:"p"},"dockerize")," in PactFlow is to wait for the network availability of a local, trusted connection on the ",(0,l.yg)("em",{parentName:"p"},"same")," host - i.e. the PactFlow application - before starting the main process and marking the service as available. Customers should be aware of the potential risk if used in other use cases."))}d.isMDXComponent=!0}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.