[ 
https://issues.apache.org/jira/browse/CASSANDRA-17993?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17624297#comment-17624297
 ] 

Gaurav Gupta commented on CASSANDRA-17993:
------------------------------------------

[https://nvd.nist.gov/vuln/detail/CVE-2021-0234] 

[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37136]

 
h2. Vulnerability
----Issuesonatype-2021-0789SeveritySonatype CVSS 3: 7.8
CVE CVSS 2.0: 0.0WeaknessSonatype CWE: 
[119|https://cwe.mitre.org/data/definitions/119.html]SourceSonatype Data 
ResearchCategoriesData
h2. Description
----Explanation
This issue has undergone the Sonatype Fast-Track process. For more information, 
please see the [Sonatype Knowledge Base 
Guide|https://guides.sonatype.com/iqserver/technical-guides/sonatype-vuln-data/#when-is-vulnerability-data-available].
Root Causeorg.wso2.carbon.analytics.test.distribution-2.0.220.zip *<=* 
wso2das-2.0.220/wso2/lib/plugins/io.netty.codec_4.1.16.Final.jar : ( 
,)AdvisoriesProject: [https://github.com/netty/netty/pull/11429]CVSS 
DetailsSonatype CVSS 3: 7.8
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
 
 
 
h2. Vulnerability
----
Issuesonatype-2019-0992SeveritySonatype CVSS 3: 5.7
CVE CVSS 2.0: 0.0WeaknessSonatype CWE: 
[494|https://cwe.mitre.org/data/definitions/494.html]SourceSonatype Data 
ResearchCategoriesData
h2. Description
----Description from Sonatypejcommander - Download of Code Without Integrity 
CheckRoot Causejoyqueue-nsr-admin-4.2.1.tar.gz *<=* lib/jcommander-1.72.jar : ( 
, 1.75)AdvisoriesProject: [https://github.com/cbeust/jcommander/issues/465]CVSS 
DetailsSonatype CVSS 3: 5.7
CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
 
 
 
 

> CVEs in Cassandra 4.0.5
> -----------------------
>
>                 Key: CASSANDRA-17993
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-17993
>             Project: Cassandra
>          Issue Type: Bug
>            Reporter: Gaurav Gupta
>            Priority: Normal
>
> Hi Team,
> We request you to fix below CVE's in Cassandra 4.0.5 
>  
> [Sonatype-2021-0234, sonatype-2019-0992, CVE-2021-37136, 
> sonatype-2021-0789|https://git.soma.salesforce.com/pages/Infrastructure-Security/ast.github.io/sonatype-2021-0234.html]



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to