[
https://issues.apache.org/jira/browse/CASSANDRA-17993?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17624297#comment-17624297
]
Gaurav Gupta commented on CASSANDRA-17993:
------------------------------------------
[https://nvd.nist.gov/vuln/detail/CVE-2021-0234]
[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37136]
h2. Vulnerability
----Issuesonatype-2021-0789SeveritySonatype CVSS 3: 7.8
CVE CVSS 2.0: 0.0WeaknessSonatype CWE:
[119|https://cwe.mitre.org/data/definitions/119.html]SourceSonatype Data
ResearchCategoriesData
h2. Description
----Explanation
This issue has undergone the Sonatype Fast-Track process. For more information,
please see the [Sonatype Knowledge Base
Guide|https://guides.sonatype.com/iqserver/technical-guides/sonatype-vuln-data/#when-is-vulnerability-data-available].
Root Causeorg.wso2.carbon.analytics.test.distribution-2.0.220.zip *<=*
wso2das-2.0.220/wso2/lib/plugins/io.netty.codec_4.1.16.Final.jar : (
,)AdvisoriesProject: [https://github.com/netty/netty/pull/11429]CVSS
DetailsSonatype CVSS 3: 7.8
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
h2. Vulnerability
----
Issuesonatype-2019-0992SeveritySonatype CVSS 3: 5.7
CVE CVSS 2.0: 0.0WeaknessSonatype CWE:
[494|https://cwe.mitre.org/data/definitions/494.html]SourceSonatype Data
ResearchCategoriesData
h2. Description
----Description from Sonatypejcommander - Download of Code Without Integrity
CheckRoot Causejoyqueue-nsr-admin-4.2.1.tar.gz *<=* lib/jcommander-1.72.jar : (
, 1.75)AdvisoriesProject: [https://github.com/cbeust/jcommander/issues/465]CVSS
DetailsSonatype CVSS 3: 5.7
CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
> CVEs in Cassandra 4.0.5
> -----------------------
>
> Key: CASSANDRA-17993
> URL: https://issues.apache.org/jira/browse/CASSANDRA-17993
> Project: Cassandra
> Issue Type: Bug
> Reporter: Gaurav Gupta
> Priority: Normal
>
> Hi Team,
> We request you to fix below CVE's in Cassandra 4.0.5
>
> [Sonatype-2021-0234, sonatype-2019-0992, CVE-2021-37136,
> sonatype-2021-0789|https://git.soma.salesforce.com/pages/Infrastructure-Security/ast.github.io/sonatype-2021-0234.html]
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]