Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): vulnerabilities found in corda-4-8-all-in-one #2064

Closed
zondervancalvez opened this issue Jun 1, 2022 · 7 comments · May be fixed by adrianbatuto/cacti#3
Closed

fix(security): vulnerabilities found in corda-4-8-all-in-one #2064

zondervancalvez opened this issue Jun 1, 2022 · 7 comments · May be fixed by adrianbatuto/cacti#3
Assignees
Labels
bug Something isn't working Corda dependencies Pull requests that update a dependency file dependent good-first-issue Good for newcomers good-first-issue-300-advanced P4 Priority 4: Low Security Related to existing or potential security vulnerabilities
Milestone

Comments

@zondervancalvez
Copy link
Contributor

zondervancalvez commented Jun 1, 2022

List of vulnerabilities found in corda-4-8-all-in-one image during Azure Container scan.

VULNERABILITY ID PACKAGE NAME SEVERITY
CVE-2021-36159 apk-tools CRITICAL
CVE-2021-30139 apk-tools HIGH
CVE-2022-28391 busybox CRITICAL
CVE-2021-28831 busybox HIGH
CVE-2021-42378 busybox HIGH
CVE-2018-15756 org.springframework:spring-core HIGH
CVE-2022-22970 org.springframework:spring-core HIGH
CVE-2022-22965 org.springframework:spring-webmvc CRITICAL
CVE-2020-5398 org.springframework:spring-webmvc HIGH
CVE-2017-18640 org.yaml:snakeyaml HIGH
CVE-2017-18640 org.yaml:snakeyaml HIGH
CVE-2017-18640 org.yaml:snakeyaml HIGH
CVE-2017-18640 org.yaml:snakeyaml HIGH

Depends on #2621

@petermetz petermetz added bug Something isn't working good-first-issue Good for newcomers dependencies Pull requests that update a dependency file Security Related to existing or potential security vulnerabilities good-first-issue-300-advanced P4 Priority 4: Low Corda labels Jun 2, 2022
@petermetz
Copy link
Contributor

P4 because the Corda AIO images are not meant to be used in production.

@charellesandig
Copy link
Contributor

Hi Peter! I'd like to work on this ticket, thank you.

charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 4, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 4, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 4, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 4, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 5, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 5, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 5, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 9, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 9, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 10, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 10, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 10, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 11, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 12, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 12, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 12, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 16, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 16, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 16, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 16, 2023
charellesandig added a commit to charellesandig/cactus that referenced this issue Jan 16, 2023
@aldousalvarez
Copy link
Contributor

Hello @jagpreetsinghsasan I am also currently helping on this one.

@github-actions
Copy link

github-actions bot commented Sep 1, 2023

@jagpreetsinghsasan jagpreetsinghsasan moved this from In Progress to Blocked in Cacti_Scrum_Project_v2_Release Sep 6, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 8, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 8, 2023
@jagpreetsinghsasan jagpreetsinghsasan moved this from Blocked to In Progress in Cacti_Scrum_Project_v2_Release Sep 8, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 8, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 8, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 8, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 11, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 11, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 12, 2023
adrianbatuto added a commit to adrianbatuto/cacti that referenced this issue Sep 13, 2023
@adrianbatuto
Copy link
Contributor

The vulnerability issues found on the Trivy scan had to do with the Corda jar files. I'll raise a ticket to corda giving them the list of vulnerabilities we have found so they can fix it. Will update this ticket with the issue ticket raised to corda once I have it.

@adrianbatuto adrianbatuto moved this from In Progress to Blocked in Cacti_Scrum_Project_v2_Release Oct 4, 2023
@petermetz
Copy link
Contributor

@adrianbatuto Could you please make the issue title unique (CVE ID or IDs of the most severe vulnerabilities is my go-to in these cases - while keeping in mind the maximum length for the commit linter at the same time)

@petermetz
Copy link
Contributor

We've retired the corda v4.8 AIO image. Also, we'll pause fixes of CVEs in test tools as they are not getting deployed into production.

@petermetz petermetz closed this as not planned Won't fix, can't repro, duplicate, stale Jul 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Corda dependencies Pull requests that update a dependency file dependent good-first-issue Good for newcomers good-first-issue-300-advanced P4 Priority 4: Low Security Related to existing or potential security vulnerabilities
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants