Uploaded image for project: 'TomEE'
  1. TomEE
  2. TOMEE-2791

TomEE plus(7.0.7) is affected by CVE-2019-12400 vulnerability

Attach filesAttach ScreenshotBulk Copy AttachmentsBulk Move AttachmentsVotersWatch issueWatchersCreate sub-taskConvert to sub-taskLinkCloneLabelsUpdate Comment AuthorReplace String in CommentUpdate Comment Visibility
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Minor
    • Resolution: Auto Closed
    • 7.0.7
    • 7.0.7
    • None
    • None

    Description

      TomEE plus version is using xmlsec-2.0.6.jar (Apache Santuario) version which is affected by vulnerability CVE-2019-12400 with CVSS score of 5.5 which is leading to potential security flaws.  
      Please confirm if this vulnerability impacts version 7.0.7 ?

      Please upgrade to 2.1.4 version which has an official fix to address this issue.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            Jayaprakash Jayaprakash
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment