Done
Details
Assignee
Former userFormer user(Deactivated)Reporter
Former userFormer user(Deactivated)Labels
Sprint
NoneFix versions
Priority
Medium
Details
Details
Assignee
Former user
Former user(Deactivated)Reporter
Former user
Former user(Deactivated)Labels
Sprint
None
Fix versions
Priority
Created February 11, 2019 at 4:45 AM
Updated July 10, 2019 at 8:03 PM
Resolved May 30, 2019 at 6:29 PM
Following vulnerability identified under CLM scan; upgrade to version specified (last column)
dcaegen2/collector/hv-ves
com.google.guava : guava : 19.0
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class
The application is vulnerable by using this component if it uses Java deserialization or GWT-RPC to deserialize untrusted data.
Upgrade to 23.6.1-jre