Graylog2 / Graylog2/graylog2-server

Vdoo Scan results

Open
#11,946 0 comments 0 reactions 1 assignee Claimed by @kroepke View on GitHub
security triaged
Dominant language
Java
Stars
8.1k
Forks
1.1k
Avg merge
1d 20h
Merged PRs (30d)
217

Description

Hello,

I made an inline scan of Graylog 4.2.5 docker using Vdoo.

Below some of the vunerabilities found for Graylog.

Could you tell me if these vulnerabilities are false-positives ?

If not, do you have any plan to fix them ? Meanwhile, have you done any CVSS scoring in the context of Graylog ?

Thanks,
Anass

com.fasterxml.jackson.core:jackson-databind :: [CVE-2020-36189](https://nvd.nist.gov/vuln/detail/CVE-2020-36189) and (CVE-2020-36188/CVE-2020-36183/CVE-2020-35728/CVE-2020-24750/CVE-2020-24616/CVE-2020-1406(0/1/2/7)/CVE-2019-16335/CVE-2019-14893/CVE-2019-14540)
io.netty:netty-handler :: [CVE-2020-11612](https://nvd.nist.gov/vuln/detail/CVE-2020-11612)
org.apache.shiro:shiro-core :: [CVE-2021-41303](https://nvd.nist.gov/vuln/detail/CVE-2021-41303) [CVE-2020-17523](https://nvd.nist.gov/vuln/detail/CVE-2020-17523) [CVE-2020-13933](https://nvd.nist.gov/vuln/detail/CVE-2020-13933) [CVE-2020-11989](https://nvd.nist.gov/vuln/detail/CVE-2020-11989)
glibc :: [CVE-2021-33574](https://nvd.nist.gov/vuln/detail/CVE-2021-33574)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.