-
Notifications
You must be signed in to change notification settings - Fork 174
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2022-32151 and CVE-2022-32158 in Version 1.11.8 #291
Comments
@tdhellmann we can see there are too many CVEs getting flagged for this jar in dependency check report. CVEs: CVE-2011-4644,CWE-287 We believe these are all FP for this project. Can we get the confirmation so that we can ask dependency check team to get it suppressed? |
@Subrhamanya thanks for reaching out. While I'm not on this project anymore (and haven't been for several years), I'm reporting this internally to try to get you an answer. |
Sure thanks. |
Any updates @tdhellmann?? If possible, can you please pull whoever is working on it?? It's like our release is getting struck due to this from past a couple of days... and it's a bit critical for us... cc: @fantavlik |
We are currently using version 1.11.8 of the Splunk Java Logging Library and have identified two critical vulnerabilities: CVE-2022-32151 and CVE-2022-32158.
Could you please provide if there is an updated version that addresses these issues or the timeline for the fix for this?
The text was updated successfully, but these errors were encountered: