eclipsesource / eclipsesource/J2V8

Potential secutiry vulnerabilities in the shared library which J2V8 depends on. Can you help upgrade to patch versions?

Open
#581 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
2.6k
Forks
387
PR merge metrics
No merged PRs in 30d

Description

Hi, @irbull , @drywolf , I'd like to report a vulnerability issue in **com.eclipsesource.j2v8:j2v8:linux_x86_64_4.8.0**.
### Issue Description
**com.eclipsesource.j2v8:j2v8:linux_x86_64_4.8.0** depends on ***1*** C library(.so). However, I noticed that the C library is vulnerable, containing the following CVEs:

`libj2v8_linux_x86_64.so` from C project **openssl(version:1.0.2j)** exposed ***4*** vulnerabilities:
[CVE-2021-3712](https://nvd.nist.gov/vuln/detail/CVE-2021-3712), [CVE-2020-1968](https://nvd.nist.gov/vuln/detail/CVE-2020-1968), [CVE-2017-3738](https://nvd.nist.gov/vuln/detail/CVE-2017-3738), [CVE-2019-1552](https://nvd.nist.gov/vuln/detail/CVE-2019-1552)

### Suggested Vulnerability Patch Versions
***openssl*** has fixed the vulnerabilities in versions ***>=1.1.1l***

Java build tools cannot report vulnerable C libraries, which may induce potential security issues to many downstream Java projects.
Could you please upgrade the above shared libraries to their patch versions?

Thanks for your help~
Best regards,
Helen Parr

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.