momo-tong / org.springframework.boot-spring-boot-2.2.10.RELEASE

0 stars 0 forks source link

liquibase-core-3.8.9.jar: 1 vulnerabilities (highest severity is: 9.8) - autoclosed #51

Closed mend-bolt-for-github[bot] closed 1 year ago

mend-bolt-for-github[bot] commented 1 year ago
Vulnerable Library - liquibase-core-3.8.9.jar

Liquibase is a tool for managing and executing database changes.

Library home page: http://www.liquibase.org/liquibase-root/liquibase-dist

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/liquibase/liquibase-core/3.8.9/liquibase-core-3.8.9.jar

Found in HEAD commit: af0de1ab054f866ea94cd6bd334c26f2afb0ba85

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (liquibase-core version) Remediation Possible**
CVE-2022-0839 Critical 9.8 liquibase-core-3.8.9.jar Direct 4.8.0

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2022-0839 ### Vulnerable Library - liquibase-core-3.8.9.jar

Liquibase is a tool for managing and executing database changes.

Library home page: http://www.liquibase.org/liquibase-root/liquibase-dist

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/liquibase/liquibase-core/3.8.9/liquibase-core-3.8.9.jar

Dependency Hierarchy: - :x: **liquibase-core-3.8.9.jar** (Vulnerable Library)

Found in HEAD commit: af0de1ab054f866ea94cd6bd334c26f2afb0ba85

Found in base branch: master

### Vulnerability Details

Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.

Publish Date: 2022-03-04

URL: CVE-2022-0839

### CVSS 3 Score Details (9.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

### Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0839

Release Date: 2022-03-04

Fix Resolution: 4.8.0

Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)