1"use strict";(self.webpackChunkpartners=self.webpackChunkpartners||[]).push([[32322],{15680:(e,t,n)=>{n.d(t,{xA:()=>p,yg:()=>y});var i=n(96540);function l(e,t,n){return t in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function a(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var i=Object.getOwnPropertySymbols(e);t&&(i=i.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),n.push.apply(n,i)}return n}function o(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?a(Object(n),!0).forEach((function(t){l(e,t,n[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):a(Object(n)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))}))}return e}function r(e,t){if(null==e)return{};var n,i,l=function(e,t){if(null==e)return{};var n,i,l={},a=Object.keys(e);for(i=0;i<a.length;i++)n=a[i],t.indexOf(n)>=0||(l[n]=e[n]);return l}(e,t);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);for(i=0;i<a.length;i++)n=a[i],t.indexOf(n)>=0||Object.prototype.propertyIsEnumerable.call(e,n)&&(l[n]=e[n])}return l}var s=i.createContext({}),u=function(e){var t=i.useContext(s),n=t;return e&&(n="function"==typeof e?e(t):o(o({},t),e)),n},p=function(e){var t=u(e.components);return i.createElement(s.Provider,{value:t},e.children)},d="mdxType",c={inlineCode:"code",wrapper:function(e){var t=e.children;return i.createElement(i.Fragment,{},t)}},g=i.forwardRef((function(e,t){var n=e.components,l=e.mdxType,a=e.originalType,s=e.parentName,p=r(e,["components","mdxType","originalType","parentName"]),d=u(n),g=l,y=d["".concat(s,".").concat(g)]||d[g]||c[g]||a;return n?i.createElement(y,o(o({ref:t},p),{},{components:n})):i.createElement(y,o({ref:t},p))}));function y(e,t){var n=arguments,l=t&&t.mdxType;if("string"==typeof e||l){var a=n.length,o=new Array(a);o[0]=g;var r={};for(var s in t)hasOwnProperty.call(t,s)&&(r[s]=t[s]);r.originalType=e,r[d]="string"==typeof e?e:l,o[1]=r;for(var u=2;u<a;u++)o[u]=n[u];return i.createElement.apply(null,o)}return i.createElement.apply(null,n)}g.displayName="MDXCreateElement"}
1,34049:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>s,contentTitle:()=>o,default:()=>c,frontMatter:()=>a,metadata:()=>r,toc:()=>u});var i=n(58168),l=(n(96540),n(15680));const a={title:"Security audit report"},o=void 0,r={unversionedId:"docs/on-premises-2x/security-audit-report",id:"docs/on-premises-2x/security-audit-report",title:"Security audit report",description:"Vulnerability scanning",source:"@site/docs/docs/on-premises-2x/security-audit-report.md",sourceDirName:"docs/on-premises-2x",slug:"/docs/on-premises-2x/security-audit-report",permalink:"/docs/on-premises-2x/security-audit-report",draft:!1,editUrl:"https://github.com/pactflow/docs.pactflow.io/edit/master/website/docs/docs/on-premises-2x/security-audit-report.md",tags:[],version:"current",lastUpdatedBy:"Matt Fellows",lastUpdatedAt:1752236466,formattedLastUpdatedAt:"Jul 11, 2025",frontMatter:{title:"Security audit report"},sidebar:"onprem",previous:{title:"On-Premises SCIM API",permalink:"/docs/on-premises-2x/scim"},next:{title:"Support policy",permalink:"/docs/on-premises-2x/support-policy"}},s={},u=[{value:"Vulnerability scanning",id:"vulnerability-scanning",level:2},{value:"Reporting vulnerabilities",id:"reporting-vulnerabilities",level:2}
1,{value:"Identifying the correct Ruby version",id:"identifying-the-correct-ruby-version",level:2},{value:"Identifying the installed gem versions",id:"identifying-the-installed-gem-versions",level:2},{value:"Known advisories",id:"known-advisories",level:2},{value:"CVE-2015-9284",id:"cve-2015-9284",level:3},{value:"Component",id:"component",level:4},{value:"CVE",id:"cve",level:4},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow",level:4},{value:"Status",id:"status",level:4},{value:"Notes",id:"notes",level:4},{value:"CVE-2021-41816",id:"cve-2021-41816",level:3},{value:"Component",id:"component-1",level:4},{value:"CVE",id:"cve-1",level:4},{value:"Status",id:"status-1",level:4},{value:"Notes",id:"notes-1",level:4},{value:"CVE-2020-36599",id:"cve-2020-36599",level:3},{value:"Description",id:"description",level:4},{value:"Component",id:"component-2",level:4},{value:"Status",id:"status-2",level:4},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow-1",level:4},{value:"Fixed versions",id:"fixed-versions",level:4},{value:"Notes",id:"notes-2",level:4},{value:"<code>libpam</code> and <code>perl</code> related security vulnerabilities",id:"libpam-and-perl-related-security-vulnerabilities",level:3},{value:"CVE-2024-10963",id:"cve-2024-10963",level:4},{value:"Affected Components",id:"affected-components",level:5},{value:"CVE",id:"cve-2",level:5},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow-2",level:5},{value:"Notes",id:"notes-3",level:5},{value:"CVE-2024-10041",id:"cve-2024-10041",level:4},{value:"Affected Components",id:"affected-components-1",level:5},{value:"CVE",id:"cve-3",level:5},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow-3",level:5},{value:"Notes",id:"notes-4",level:5},{value:"CVE-2025-40909",id:"cve-2025-40909",level:4},{value:"Affected Components",id:"affected-components-2",level:5},{value:"CVE",id:"cve-4",level:5},{value:"Detectable in versions of PactFlow",id:"detectable-in-versions-of-pactflow-4",level:5},{value:"Notes",id:"notes-5",level:5},{value:"Mitigation guidance",id:"mitigation-guidance",level:3}],p={toc:u},d="wrapper";function c(e){let{components:t,...n}=e;return(0,l.yg)(d,(0,i.A)({},p,n,{components:t,mdxType:"MDXLayout"}),(0,l.yg)("h2",{id:"vulnerability-scanning"},"Vulnerability scanning"),(0,l.yg)("p",null,"PactFlow uses the following tools to ensure the On-Premises image is kept as secure as possible."),(0,l.yg)("ul",null,(0,l.yg)("li",{parentName:"ul"},"Bundler Audit"),(0,l.yg)("li",{parentName:"ul"},"NPM audit"),(0,l.yg)("li",{parentName:"ul"},"Trivy"),(0,l.yg)("li",{parentName:"ul"},"Quay Security Scanner"),(0,l.yg)("li",{parentName:"ul"},"Amazon ECR Image scanning")),(0,l.yg)("h2",{id:"reporting-vulnerabilities"},"Reporting vulnerabilities"),(0,l.yg)("p",null,"To report a vulnerability, please ",(0,l.yg)("a",{parentName:"p",href:"https://smartbear.com/security/"},"contact security")," and ensure you include the relevant CVE, and the name and/or path to the vulnerable component."),(0,l.yg)("h2",{id:"identifying-the-correct-ruby-version"},"Identifying the correct Ruby version"),(0,l.yg)("p",null,"Many scanning tools have trouble identifying the correct version of Ruby installed on an image because Ruby stores its gems in a directory path that uses the minor version of Ruby (eg. ",(0,l.yg)("inlineCode",{parentName:"p"},"2.7.0"),") rather than the patch version (eg. ",(0,l.yg)("inlineCode",{parentName:"p"},"2.7.6"),"). This can be demonstrated by running the following command:"),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre",className:"language-shell"},"docker run --rm -it --entrypoint gem quay.io/pactflow/enterprise:latest environment\n")),(0,l.yg)("p",null,"Example output (note the ",(0,l.yg)("inlineCode",{parentName:"p"},"RUBY VERSION")," of ",(0,l.yg)("inlineCode",{parentName:"p"},"2.7.6")," while the ",(0,l.yg)("inlineCode",{parentName:"p"},"GEM PATHS")," use ",(0,l.yg)("inlineCode",{parentName:"p"},"2.7.0"),"):"),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre",className:"language-shell"},'RubyGems Environment:\n - RUBYGEMS VERSION: 3.1.6\n - RUBY VERSION: 2.7.6 (2022-04-12 patchlevel 219) [x86_64-linux-musl]\n - INSTALLATION DIRECTORY: /usr/local/bundle\n - USER INSTALLATION DIRECTORY: /root/.gem/ruby/2.7.0\n - RUBY EXECUTABLE: /usr/local/bin/ruby\n - GIT EXECUTABLE:\n - EXECUTABLE DIRECTORY: /usr/local/bundle/bin\n - SPEC CACHE DIRECTORY: /root/.gem/specs\n - SYSTEM CONFIGURATION DIRECTORY: /usr/local/etc\n - RUBYGEMS PLATFORMS:\n - ruby\n - x86_64-linux-musl\n - GEM PATHS:\n - /usr/local/bundle\n - /root/.gem/ruby/2.7.0\n - /usr/local/lib/ruby/gems/2.7.0\n - GEM CONFIGURATION:\n - :update_sources => true\n - :verbose => true\n - :backtrace => false\n - :bulk_threshold => 1000\n - "install" => "--no-document"\n - "update" => "--no-document"\n - REMOTE SOURCES:\n - https://rubygems.org/\n - SHELL PATH:\n - /usr/local/bundle/bin\n - /usr/local/sbin\n - /usr/local/bin\n - /usr/sbin\n - /usr/bin\n - /sbin\n - /bin\n')),(0,l.yg)("p",null,"The difficulty that tools have in identifying the correct version of Ruby can lead to false positives being reported. Please check the version of Ruby before submitting a vulnerability report."),(0,l.yg)("h2",{id:"identifying-the-installed-gem-versions"},"Identifying the installed gem versions"),(0,l.yg)("p",null,"To list the gems installed on the PactFlow image run:"),(0,l.yg)("pre",null,(0,l.yg)("c
1ode",{parentName:"pre"},'docker run --rm -it --entrypoint gem quay.io/pactflow/enterprise:latest "list"\n')),(0,l.yg)("h2",{id:"known-advisories"},"Known advisories"),(0,l.yg)("h3",{id:"cve-2015-9284"},"CVE-2015-9284"),(0,l.yg)("h4",{id:"component"},"Component"),(0,l.yg)("p",null,"omniauth gem"),(0,l.yg)("h4",{id:"cve"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2015-9284"},"https://nvd.nist.gov/vuln/detail/CVE-2015-9284")),(0,l.yg)("h4",{id:"detectable-in-versions-of-pactflow"},"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"All."),(0,l.yg)("h4",{id:"status"},"Status"),(0,l.yg)("p",null,"Non-exploitable."),(0,l.yg)("h4",{id:"notes"},"Notes"),(0,l.yg)("p",null,"This CVE is a CSRF vulnerability during sign in. This vulnerability is only exploitable if the initial request from the service provider to the identify provider is vulnerable to a CSRF attack because it uses a GET request without any CSRF protection. In PactFlow, this is not possible as PactFlow uses a POST request method with a CSRF token for the initial request to the IDP, as per the mitigation instructions ",(0,l.yg)("a",{parentName:"p",href:"https://github.com/omniauth/omniauth/wiki/Resolving-CVE-2015-9284"},"here"),"."),(0,l.yg)("p",null,"This can be observed by viewing the source of the login form."),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre",className:"language-html"},'<form action="https://example.com/auth/saml" method="post">\n <input type="hidden" name="authenticity_token" value="i_nnrcJziCKKNMb-FRQtxot2ZE6nsNpIhC_AtsK5Boc=">\n <button type="submit">SAML</button>\n</form>\n')),(0,l.yg)("h3",{id:"cve-2021-41816"},"CVE-2021-41816"),(0,l.yg)("h4",{id:"component-1"},"Component"),(0,l.yg)("p",null,"The cgi library included in Ruby before 2.7.5 and 3.x before 3.0.3, and the ",(0,l.yg)("a",{parentName:"p",href:"https://rubygems.org/gems/cgi"},"cgi gem")," before 0.3.1."),(0,l.yg)("h4",{id:"cve-1"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2021-41816"},"https://nvd.nist.gov/vuln/detail/CVE-2021-41816")),(0,l.yg)("h4",{id:"status-1"},"Status"),(0,l.yg)("p",null,"False positive."),(0,l.yg)("h4",{id:"notes-1"},"Notes"),(0,l.yg)("p",null,"This vulnerability only affects platforms that use a 4 byte long data type, typically Windows. The PactFlow base image uses 64 bit Ubuntu Linux, which uses an ",(0,l.yg)("a",{parentName:"p",href:"https://www.ibm.com/docs/en/ibm-mq/9.0?topic=platforms-standard-data-types-unix-linux-windows"},"8 byte long"),"."),(0,l.yg)("h3",{id:"cve-2020-36599"},"CVE-2020-36599"),(0,l.yg)("h4",{id:"description"},"Description"),(0,l.yg)("p",null,"lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value."),(0,l.yg)("h4",{id:"component-2"},"Component"),(0,l.yg)("p",null,"omniauth gem"),(0,l.yg)("h4",{id:"status-2"},"Status"),(0,l.yg)("p",null,"Non-exploitable."),(0,l.yg)("h4",{id:"detectable-in-versions-of-pactflow-1"},"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"Up to and including 1.19.2."),(0,l.yg)("h4",{id:"fixed-versions"},"Fixed versions"),(0,l.yg)("p",null,"1.19.3 and later."),(0,l.yg)("h4",{id:"notes-2"},"Notes"),(0,l.yg)("p",null,"PactFlow uses a custom failure endpoint so the vulnerable code is never executed."),(0,l.yg)("h3",{id:"libpam-and-perl-related-security-vulnerabilities"},(0,l.yg)("inlineCode",{parentName:"h3"},"libpam")," and ",(0,l.yg)("inlineCode",{parentName:"h3"},"perl")," related security vulnerabilities"),(0,l.yg)("p",null,"The following CVEs affect the ",(0,l.yg)("inlineCode",{parentName:"p"},"libpam")," and ",(0,l.yg)("inlineCode",{parentName:"p"},"perl")," libraries included in the base operating system used by PactFlow\u2019s Docker image (Ubuntu 24.04). These packages are marked as essential system dependencies, and removing them would break standard package (",(0,l.yg)("inlineCode",{parentName:"p"},"apt"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"dpkg"),") and user management functionality within the container."),(0,l.yg)("p",null,"We are shipping the image with these packages included, as they are required for basic system operation. PactFlow itself does ",(0,l.yg)("strong",{parentName:"p"},"not")," use the PAM libraries at runtime. If your internal security policies require their removal, see the mitigation guidance below."),(0,l.yg)("h4",{id:"cve-2024-10963"},"CVE-2024-10963"),(0,l.yg)("h5",{id:"affected-components"},"Affected Components"),(0,l.yg)("ul",null,(0,l.yg)("li",{parentName:"ul"},"libpam0g"),(0,l.yg)("li",{parentName:"ul"},"libpam-modules"),(0,l.yg)("li",{parentName:"ul"},"libpam-runtime"),(0,l.yg)("li",{parentName:"ul"},"libpam-modules-bin",(0,l.yg)("br",{parentName:"li"}),(0,l.yg)("em",{parentName:"li"},"Version:")," 1.5.3-5")),(0,l.yg)("h5",{id:"cve-2"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2024-10963"},"https://nvd.nist.gov/vuln/detail/CVE-2024-10963")),(0,l.yg)("h5",{id:"detectable-in-versions-of-pactflow-2"}
1,"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"2.0.0 and later"),(0,l.yg)("h5",{id:"notes-3"},"Notes"),(0,l.yg)("p",null,"These libraries are not used directly by PactFlow. They are included only to satisfy essential system package dependencies (e.g. ",(0,l.yg)("inlineCode",{parentName:"p"},"login"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"passwd"),"). Removing them using normal package tools will result in a broken package state."),(0,l.yg)("h4",{id:"cve-2024-10041"},"CVE-2024-10041"),(0,l.yg)("h5",{id:"affected-components-1"},"Affected Components"),(0,l.yg)("ul",null,(0,l.yg)("li",{parentName:"ul"},"libpam0g"),(0,l.yg)("li",{parentName:"ul"},"libpam-modules"),(0,l.yg)("li",{parentName:"ul"},"libpam-runtime"),(0,l.yg)("li",{parentName:"ul"},"libpam-modules-bin",(0,l.yg)("br",{parentName:"li"}),(0,l.yg)("em",{parentName:"li"},"Version:")," 1.5.3-5")),(0,l.yg)("h5",{id:"cve-3"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2024-10041"},"https://nvd.nist.gov/vuln/detail/CVE-2024-10041")),(0,l.yg)("h5",{id:"detectable-in-versions-of-pactflow-3"},"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"2.0.0 and later"),(0,l.yg)("h5",{id:"notes-4"},"Notes"),(0,l.yg)("p",null,"As above \u2014 required only for essential base image functionality, and not invoked or referenced by PactFlow."),(0,l.yg)("h4",{id:"cve-2025-40909"},"CVE-2025-40909"),(0,l.yg)("h5",{id:"affected-components-2"},"Affected Components"),(0,l.yg)("ul",null,(0,l.yg)("li",{parentName:"ul"},"perl"),(0,l.yg)("li",{parentName:"ul"},"perl-base"),(0,l.yg)("li",{parentName:"ul"},"perl-modules-5.38"),(0,l.yg)("li",{parentName:"ul"},"libperl5.38t64\n",(0,l.yg)("em",{parentName:"li"},"Version:")," 5.38.2-3.2")),(0,l.yg)("h5",{id:"cve-4"},"CVE"),(0,l.yg)("p",null,(0,l.yg)("a",{parentName:"p",href:"https://nvd.nist.gov/vuln/detail/CVE-2025-40909"},"https://nvd.nist.gov/vuln/detail/CVE-2024-10963")),(0,l.yg)("h5",{id:"detectable-in-versions-of-pactflow-4"},"Detectable in versions of PactFlow"),(0,l.yg)("p",null,"2.0.0 and later"),(0,l.yg)("h5",{id:"notes-5"},"Notes"),(0,l.yg)("p",null,"As above \u2014 required only for essential base image functionality, and not invoked or referenced by PactFlow."),(0,l.yg)("h3",{id:"mitigation-guidance"},"Mitigation guidance"),(0,l.yg)("p",null,"If you must remove the ",(0,l.yg)("inlineCode",{parentName:"p"},"libpam*")," packages for compliance reasons:"),(0,l.yg)("ol",null,(0,l.yg)("li",{parentName:"ol"},"Be aware that this action may break the container\u2019s ability to use ",(0,l.yg)("inlineCode",{parentName:"li"},"apt"),", ",(0,l.yg)("inlineCode",{parentName:"li"},"apt-get"),", or ",(0,l.yg)("inlineCode",{parentName:"li"},"dpkg"),"."),(0,l.yg)("li",{parentName:"ol"},"You must force-remove the packages using ",(0,l.yg)("inlineCode",{parentName:"li"},"dpkg")," with dependency resolution disabled:")),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre",className:"language-sh"},"dpkg -r --force-depends libpam-modules libpam-runtime libpam0g libpam-modules-bin login passwd\n")),(0,l.yg)("ol",{start:3},(0,l.yg)("li",{parentName:"ol"},"This may prevent future upgrades or installation of packages within the running container."),(0,l.yg)("li",{parentName:"ol"},"PactFlow will continue to function correctly, but package management inside the container will be unsupported.")),(0,l.yg)("blockquote",null,(0,l.yg)("p",{parentName:"blockquote"},(0,l.yg)("strong",{parentName:"p"},"Warning:")," This operation is not recommended unless you understand and accept the trade-offs.")))}c.isMDXComponent=!0}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.