brightcove / cloud-custodian

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
https://cloudcustodian.io
Apache License 2.0
0 stars 0 forks source link

github.com/aws/amazon-ssm-agent-2.3.235.0: 15 vulnerabilities (highest severity is: 9.8) - autoclosed #70

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 2 years ago
Vulnerable Library - github.com/aws/amazon-ssm-agent-2.3.235.0

Agent to enable remote management of your Amazon EC2 instance configuration.

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (github.com/aws/amazon-ssm-agent version) Remediation Available
CVE-2018-1285 High 9.8 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct log4net - 2.0.10
CVE-2018-17142 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct net- go1.11.1
CVE-2020-27813 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct v1.4.1
CVE-2018-17143 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct net- go1.11.1
CVE-2021-27918 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct 1.15.9, 1.16.1
CVE-2018-17847 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct golang-golang-x-net-dev - 1:0.0+git20181201.351d144+dfsg-3
CVE-2018-17848 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct golang-golang-x-net-dev - 1:0.0+git20181201.351d144+dfsg-3
CVE-2021-33194 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct golang.org/x/net - v0.0.0-20210520170846-37e1c6afe023
CVE-2018-17846 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct golang-golang-x-net-dev - 1:0.0+git20181201.351d144+dfsg-3
CVE-2021-44716 High 7.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct github.com/golang/net - 491a49abca63de5e07ef554052d180a1b5fe2d70
CVE-2012-6708 Medium 6.1 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct jQuery - v1.9.0
CVE-2020-11022 Medium 6.1 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct jQuery - 3.5.0
CVE-2015-9251 Medium 6.1 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct jQuery - 3.0.0
CVE-2020-8911 Medium 5.6 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct v1.34.1
CVE-2020-8912 Low 2.5 github.com/aws/amazon-ssm-agent-2.3.235.0 Direct v1.34.0

Details

CVE-2018-1285 ### Vulnerable Library - github.com/aws/amazon-ssm-agent-2.3.235.0

Agent to enable remote management of your Amazon EC2 instance configuration.

Dependency Hierarchy: - :x: **github.com/aws/amazon-ssm-agent-2.3.235.0** (Vulnerable Library)

Found in base branch: brightcove

### Vulnerability Details

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

Publish Date: 2020-05-11

URL: CVE-2018-1285

### CVSS 3 Score Details (9.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

### Suggested Fix

Type: Upgrade version

Release Date: 2020-05-11

Fix Resolution: log4net - 2.0.10

CVE-2018-17142 ### Vulnerable Library - github.com/aws/amazon-ssm-agent-2.3.235.0

Agent to enable remote management of your Amazon EC2 instance configuration.

Dependency Hierarchy: - :x: **github.com/aws/amazon-ssm-agent-2.3.235.0** (Vulnerable Library)

Found in base branch: brightcove

### Vulnerability Details

The html package (aka x/net/html) through 2018-09-17 in Go mishandles