Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issues with CLI #58

Open
ctwise opened this issue Oct 16, 2020 · 4 comments
Open

Security issues with CLI #58

ctwise opened this issue Oct 16, 2020 · 4 comments
Assignees
Labels
bug Something isn't working

Comments

@ctwise
Copy link

ctwise commented Oct 16, 2020

CVE-2019-17571, CVE-2020-5421, and CVE-2020-9488 were all found in the current client. These are:

CVE-2019-17571 - critical - log4j_log4 1.2.17
CVE-2020-5421 - medium - spring-core_spring-core 5.2.4
CVE-2020-9488 - low - log4j_log4j 1.2.17

@ctwise ctwise added the bug Something isn't working label Oct 16, 2020
@kmcdon83
Copy link

Hi @ctwise , thank you for reaching out and for providing these details.

We are actively working to address these references (both log4j and spring core) that are found within our common client library in an upcoming release.

We have previously assessed the critical log4j vulnerability and based on the context of our use had deemed it not exploitable. That said, we will ensure this is addressed.

Thanks.

@gitnubster
Copy link

How active is this actually? Nearly 2 years further, no progress reported here. No release either.

@gitnubster
Copy link

It looks there actually is a newer version. Just not published to the world... something broken in the release chain?

@gitnubster
Copy link

I found the download link, but it would be great it becomes available on npmjs.org. There is an old version published 1.0.1. Newer ones aren't there. This makes the package @checkmarx/cx-common-js-client think that 1.0.1 is the latest version also.
Though is marked as optional dependency, see https://github.com/checkmarx-ltd/cx-common-js-client/blob/master/package.json

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

4 participants