julz0815 / test-action

0 stars 1 forks source link

CVE: 2017-3586 found in MySQL java connector - Version: 5.1.35 [JAVA] #243

Closed github-actions[bot] closed 1 year ago

github-actions[bot] commented 1 year ago

Veracode Software Composition Analysis

Attribute Details
Library MySQL java connector
Description MySQL java connector
Language JAVA
Vulnerability Usable Expired Certificates
Vulnerability description mysql-connector-java doesn't check the server's SSL certificate for an expiration date before it establishes the SSL connection. This would allow attackers to use an expired certificate to make requests to the server.
CVE 2017-3586
CVSS score 5.5
Vulnerability present in version/s 5.1.21-5.1.41
Found library version/s 5.1.35
Vulnerability fixed in version 5.1.42
Library latest version 8.0.31
Fix

Links:

github-actions[bot] commented 1 year ago

Veracode issue link to PR: https://github.com/julz0815/test-action/pull/184