Graylog2 / Graylog2/graylog2-server
Vdoo Scan results
- Dominant language
- Java
- Stars
- 8.1k
- Forks
- 1.1k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 217
Description
Hello,
I made an inline scan of Graylog 4.2.5 docker using Vdoo.
Below some of the vunerabilities found for Graylog.
Could you tell me if these vulnerabilities are false-positives ?
If not, do you have any plan to fix them ? Meanwhile, have you done any CVSS scoring in the context of Graylog ?
Thanks,
Anass
com.fasterxml.jackson.core:jackson-databind :: [CVE-2020-36189](https://nvd.nist.gov/vuln/detail/CVE-2020-36189) and (CVE-2020-36188/CVE-2020-36183/CVE-2020-35728/CVE-2020-24750/CVE-2020-24616/CVE-2020-1406(0/1/2/7)/CVE-2019-16335/CVE-2019-14893/CVE-2019-14540)
io.netty:netty-handler :: [CVE-2020-11612](https://nvd.nist.gov/vuln/detail/CVE-2020-11612)
org.apache.shiro:shiro-core :: [CVE-2021-41303](https://nvd.nist.gov/vuln/detail/CVE-2021-41303) [CVE-2020-17523](https://nvd.nist.gov/vuln/detail/CVE-2020-17523) [CVE-2020-13933](https://nvd.nist.gov/vuln/detail/CVE-2020-13933) [CVE-2020-11989](https://nvd.nist.gov/vuln/detail/CVE-2020-11989)
glibc :: [CVE-2021-33574](https://nvd.nist.gov/vuln/detail/CVE-2021-33574)
Contributor guide
Assessment
This issue has not been assessed yet.