Skip to content

Vulnerability and POM reorganization.

Daniel Scholl requested to merge vulnerabilities into master

Vulnerability Fix: Updates to pom.xml

The following outlines the resolution and remaining issues for vulnerabilities identified in the pom.xml file. Improvements include reductions in critical, high, and medium vulnerabilities.


Key Improvements:

  1. Reduced Vulnerabilities

    • Original Total: 24 (Critical: 1, High: 7, Medium: 15, Low: 1)
    • Updated Total: 10 (Critical: 0, High: 3, Medium: 6, Low: 1)
  2. Critical Issues Resolved


Details of Fixed Vulnerabilities:

  1. ch.qos.logback:logback-core

    • Vulnerability: CVE-2024-12798
    • Severity: Medium
    • Issue: Arbitrary code execution via JaninoEventEvaluator.
    • Resolution: Upgraded from 1.5.6 to 1.5.13.
  2. com.azure:azure-identity

    • Vulnerability: CVE-2024-35255
    • Severity: Medium
    • Issue: Elevation of privilege in Azure Identity Libraries.
    • Resolution: Upgraded to 1.12.2.
  3. org.apache.tomcat:tomcat-catalina


Remaining Vulnerabilities:

While significant progress has been made, several high and medium vulnerabilities remain, including:

  1. High Severity:

    • com.nimbusds:nimbus-jose-jwtCVE-2023-52428
      • Issue: Denial of service via large JWE p2c header.
      • Resolution Pending: Upgrade to 9.37.2.
  2. Medium Severity:

    • commons-io:commons-ioCVE-2024-47554
      • Issue: Denial of service attack on untrusted input to XmlStreamReader.
      • Resolution Pending: Upgrade to 2.14.0.
  3. Other:

    • Multiple vulnerabilities in org.springframework and software.amazon.ion.

Summary:

The latest update significantly reduces the severity of vulnerabilities while fixing all critical issues.

Edited by Daniel Scholl

Merge request reports

Loading