Uploaded image for project: 'ActiveMQ Classic'
  1. ActiveMQ Classic
  2. AMQ-7432

Vulnerable dependencies in your project.(CVEs)

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 5.16.0, 5.15.12
    • AMQP, Broker, LevelDB, MQTT
    • None

    Description

      I found your project used some dependencies that contain CVEs. To prevent potential security risks it may cause, I suggest to update the library dependency. Please note the following details.

      Vulnerable Library Version: org.apache.hadoop : hadoop-core : 1.0.4
      CVE ID: [CVE-2013-2192](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2192)
      Import Path: activemq-leveldb-store/pom.xml
      Suggested Safe Versions: 1.2.1

      Vulnerable Library Version: io.netty : netty-codec-http : 4.1.43.Final
      CVE ID: [CVE-2019-20444](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20444), [CVE-2020-7238](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7238), [CVE-2019-20445](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20445)
      Import Path: activemq-amqp/pom.xml
      Suggested Safe Versions: 4.1.44.Final, 4.1.45.Final, 5.0.0.Alpha1, 5.0.0.Alpha2

      Vulnerable Library Version: org.fusesource.mqtt-client : mqtt-client : 1.15
      CVE ID: [CVE-2019-0222](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0222)
      Import Path: activemq-mqtt/pom.xml, activemq-unit-tests/pom.xml
      Suggested Safe Versions: 1.16

      Vulnerable Library Version: com.fasterxml.jackson.core : jackson-databind : 2.9.10.1
      CVE ID: [CVE-2020-8840](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840), [CVE-2019-20330](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330)
      Import Path: activemq-broker/pom.xml, assembly/pom.xml, activemq-partition/pom.xml, activemq-leveldb-store/pom.xml, activemq-console/pom.xml
      Suggested Safe Versions: 2.10.0, 2.10.1, 2.10.2, 2.9.10.3

      Attachments

        Activity

          People

            jbonofre Jean-Baptiste Onofré
            XuCY XuCongying
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 1h 20m
                1h 20m