-
-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2021-35516 in dependency org.apache.commons:commons-compress #4308
Comments
Thanks for bringing this to our attention @redcatbear. Please note that this is not an attack vector for normal Testcontainer usage scenarios and is unlikely to have exploitable consequences. |
Thanks for recognizing the issue. I agree that the use case for an exploit is not the typical testcontainer scenario. Still it is a good idea to keep ones software as clean as possible and the fix in this case is luckily trivial. |
Just as an addition: @kiview Do you have an estimate on when the dependency bump will be released? |
This issue is now over 3 month old. Any update on when this will be addressed? @kiview |
This seems to be fixed (at least in |
@moritzluedtke sorry, looks like we missed this in the release notes. Will add now. |
@rnorth Thank you! |
Closing due to it was fixed last year. |
Situation
Testcontainers depends on
org.apache.commons:commons-compress
version 1.20, which has a reported vulnerability CVE-2021-35516. Specially crafted archives can be used to allocate large amounts of memory, resulting in DoS.Solution
Please update dependency:
The text was updated successfully, but these errors were encountered: