Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Known Security Vulnerabilities to be fixed #110

Open
dicaeffe opened this issue Dec 11, 2020 · 0 comments
Open

Known Security Vulnerabilities to be fixed #110

dicaeffe opened this issue Dec 11, 2020 · 0 comments

Comments

@dicaeffe
Copy link

Hello,
version 9.0 (and uppers) of Pentaho and of Pentaho SAML plugin have few known CVEs (Common Vulnerabilities and Exposures) due to their dependencies.

Is possible to fix those security issues by updating the versions reported below?

Dependencies inherited from Pentaho

  • Has been already requested a fix on Pentaho Platform side.
  • Issue: 4788

Dependencies specific of Pentaho SAML Plugin

the version of dependencies reported below is overwritten by the plugin and needs to be fixed because doesn't inherit those of Pentaho Platform.


Apache Commons FileUpload

  • CVE - 1 issue: CVE-2016-1000031
  • Used Version: 1.3.2
  • Fix Version: 1.3.3
  • update requested on Pentaho: >1.4

karaf

org.apache.xmlgraphics:batik-bridge

Spring Security

  • CVE - 2 issues: CVE-2014-3527, CVE-2014-0097
  • Used Version: 3.1.4.RELEASE
  • Fix Version: 3.1.7.RELEASE
  • update requested on Pentaho: >4.2.9.RELEASE

spring-framework

  • CVE - 2 issues: CVE-2014-3625, CVE-2014-3578
  • Used Version: 3.2.11.RELEASE
  • Fix Version: 3.2.12.RELEASE (last minor: EOL 3.2.18.RELEASE)
  • update requested on Pentaho: >4.3.22.RELEASE
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant