OSSIndex / vulns

Report missing advisories and corrections on OSS Index
17 stars 12 forks source link

org.jxmpp libraries are not affected by CVE-2014-0363, CVE-2014-0364 or CVE-2016-10027 #206

Closed balgillo closed 3 years ago

balgillo commented 3 years ago

Vulnerability URL Provide the URL to the vulnerability.

Component URL Provide the URL to the component.

Description

These vulnerabilities affected old versions of Smack library, a different org.igniterealtime project. It looks like the same version numbering has been assumed for org.jxmpp projects, because the page says that this affects versions up to 4.0. But the latest is 1.0.2.

ken-duck commented 3 years ago

Thanks for the heads up. OSS Index assigned the vulnerabilities based on the jxmpp-* packages in maven claiming that their sources were here: https://github.com/igniterealtime/Smack

Where indeed the sources should have been here: https://github.com/igniterealtime/jxmpp/releases

We have fixed this in our local data and it should be public in OSS Index by sometime tomorrow.

balgillo commented 3 years ago

Great, thanks for addressing this. I can see it's corrected now.