cBioPortal / cbioportal

cBioPortal for Cancer Genomics
https://cbioportal.org
GNU Affero General Public License v3.0
628 stars 480 forks source link

2 critical vulnerabilities in version 6.0.5 #10834

Open TJMKuijpers opened 3 months ago

TJMKuijpers commented 3 months ago

Snyk listed two critical vulnerabilities in cbioportal 6.0.5:

  1. org.redisson:redisson Deserialization of Untrusted Data
  2. com.fasterxml.woodstox:woodstox-core XML External Entity (XXE) Injection

Issue 1 can be fixed by updating org.redisson:redisson@3.12.2 to org.redisson:redisson@3.22.0 Issue 2 can be fixed by updatin com.fasterxml.woodstox:woodstox-core@5.0.3 to com.fasterxml.woodstox:woodstox-core@5.3.0