Accepted Vulnerabilities

Vulnerabilities that have been accepted across the whole organization

CVERiskAssetAccepted atAutomatically reopened for revalidationJustification
CVE-2024-61194.25
devguard
Tue Dec 03 2024Wed Apr 02 2025You are right. We are using a reverse proxy. Devguard starts with plain http handler. Using a Service-Mesh should be encouraged.
CVE-2024-288633
devguard-web
Tue Dec 03 2024Wed Apr 02 2025We cannot update this dependency. It is deep down in nodejs. Since we are not generating any subfolders or untaring anything, this can be accepted.