Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request to fix CVEs found in Maxwell v1.41.0 #2081

Open
aahirsch opened this issue Feb 12, 2024 · 1 comment
Open

Request to fix CVEs found in Maxwell v1.41.0 #2081

aahirsch opened this issue Feb 12, 2024 · 1 comment

Comments

@aahirsch
Copy link

Hello, I would like to file a CVE fix request for Maxwell v1.41.0. Twistlock shows the following high severity CVEs.

CVE-2022-41881
CVE-2022-45688
CVE-2023-2976
CVE-2023-34455
CVE-2023-36478
CVE-2023-39410
CVE-2023-43642
CVE-2023-44487
CVE-2023-5072

GHSA-xpw8-rcwv-8f8p
(including more info as no CVE yet filed for this) PRISMA-2023-0067 (Severity: high | CVSS: 7.50 | Package: com.fasterxml.jackson.core_jackson-core | Version: 2.13.1 | Status: fixed in 2.15.0 com.fasterxml.jackson.core_jackson-core package > 9 months ago | Published: > 9 months | Description: com.fasterxml.jackson.core_jackson-core package versions before 2.15.0 are vulnerable to Denial of Service (DoS). The package does not properly restri...

@osheroff
Copy link
Collaborator

Hi Alex,
patches welcome!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants