KDWSS / dd-trace-java

Datadog APM client for Java
https://docs.datadoghq.com/tracing/languages/java
Apache License 2.0
0 stars 0 forks source link

CVE-2016-1000031 (High) detected in multiple libraries - autoclosed #99

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 3 years ago

CVE-2016-1000031 - High Severity Vulnerability

Vulnerable Libraries - commons-fileupload-1.1.1.jar, commons-fileupload-1.3.2.jar, commons-fileupload-1.3.1.jar

commons-fileupload-1.1.1.jar

The FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications.

Path to dependency file: /dd-java-agent/instrumentation/axis-2/axis-2.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/commons-fileupload/commons-fileupload/1.1.1/d587a50727ba905aad13de9ea119081403bf6823/commons-fileupload-1.1.1.jar

Dependency Hierarchy: - axis2-kernel-1.3.jar (Root Library) - :x: **commons-fileupload-1.1.1.jar** (Vulnerable Library)

commons-fileupload-1.3.2.jar

The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications.

Path to dependency file: /dd-java-agent/appsec/weblog/weblog-spring-app/weblog-spring-app.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/commons-fileupload/commons-fileupload/1.3.2/5d7491ed6ebd02b6a8d2305f8e6b7fe5dbd95f72/commons-fileupload-1.3.2.jar

Dependency Hierarchy: - grails-web-fileupload-3.2.10.jar (Root Library) - :x: **commons-fileupload-1.3.2.jar** (Vulnerable Library)

commons-fileupload-1.3.1.jar

The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications.

Library home page: http://commons.apache.org/proper/commons-fileupload/

Path to dependency file: /dd-java-agent/instrumentation/finatra-2.9/finatra-2.9.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/commons-fileupload/commons-fileupload/1.3.1/c621b54583719ac0310404463d6d99db27e1052c/commons-fileupload-1.3.1.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/commons-fileupload/commons-fileupload/1.3.1/c621b54583719ac0310404463d6d99db27e1052c/commons-fileupload-1.3.1.jar

Dependency Hierarchy: - synapse-nhttp-transport-3.0.0.jar (Root Library) - axis2-transport-http-1.7.3.jar - axis2-kernel-1.7.3.jar - :x: **commons-fileupload-1.3.1.jar** (Vulnerable Library)

Found in HEAD commit: 2819174635979a19573ec0ce8e3e2b63a3848079

Found in base branch: master

Vulnerability Details

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

Publish Date: 2016-10-25

URL: CVE-2016-1000031

CVSS 3 Score Details (9.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000031

Release Date: 2016-10-25

Fix Resolution (commons-fileupload:commons-fileupload): 1.3.3

Direct dependency fix Resolution (org.apache.axis2:axis2-kernel): 1.7.6

Fix Resolution (commons-fileupload:commons-fileupload): 1.3.3

Direct dependency fix Resolution (org.grails:grails-web-fileupload): 3.3.0

Fix Resolution (commons-fileupload:commons-fileupload): 1.3.3

Direct dependency fix Resolution (org.apache.synapse:synapse-nhttp-transport): 3.0.1


:rescue_worker_helmet: Automatic Remediation is available for this issue

mend-for-github-com[bot] commented 1 year ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.