...
This page keeps track of known CVE issues in libraries that are distributed with Delft-FEWS and the upgrade strategy of these libraries. The Common Vulnerability Scoring System (CVSS) of severity Critical and High are reported here.
date | CVE | library | description | versions | Risk for Delft-FEWS | JIRA | upgrade strategy |
---|
November 2023202336052azurecore*.jarazure-identity-*.jarAzure CLI REST Command Information Disclosure Vulnerability
The Microsoft Security Response Center (MSRC) was made aware of a vulnerability where Azure Command-Line Interface (CLI) could expose sensitive information, including credentials, through GitHub Actions logs. The researcher, from Palo Alto Networks Prisma Cloud, found that Azure CLI commands could be used to show sensitive data and output to Continuous Integration and Continuous Deployment (CI/CD) logs. Microsoft recommends that customers update to the latest version of Azure CLI (2.54) and follow the guidance provided below to help prevent inadvertently exposing secrets through CI/CD logs. A notification in the Azure Portal was sent to customers who recently used Azure CLI commands informing them of an available update. | This is a very specific use case where the role these Java libraries could play is not clear. FEWS is not using this library in the context of a CLI or Github actions so this OWASP alert is considered a false positive. | November 2023 | CVE-2023-36415 | azure-identity-*.jar | Azure Identity SDK Remote Code Execution VulnerabilityAbove is the only information supplied
For the current 1.11.0 version we consider this a false alert for a vulnerability that needs to be addressed in the .net based Azure SDK. so it will be suppressed, specifically for CVE-2023-36415
31.1.jar | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions... A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed.
FEWS uses the Geotools library, not GeoServer, the WFS (Web Feature server) implementation in FEWS is a 'Simple" profile implementation of the WFS standard which is read-only, does not include XPath expression and does not use the vulnerable gt-complex-x.y.jar library reported here, Therefore this is considered a false positive
| 2021-02 - current | False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey |
---|
|
|
2021.02 - current | False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution | columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
30236October 2023 | False positive, no action required |
February 2024 | CVE- |
202345853libz.so.1.2.13
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.The main author, Mark Adler states (github):Minizip is not part of zlib. The source code is provided in the contrib directory of the zlib distribution, along with several other such contributions, as a courtesy. This is not a zlib vulnerability.Additionally, zlib.def has been checked to verify that at least the windows version contains no minizip methods.2022.02 - current | The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data. FEWS uses a more recent version (1.2.13 - 1.3.1) but apparently the OWASP dependency checker is not able to detect this, therefore we consider this a false alarm. | 2022.02 - current |
False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS-27692 |
---|
|
| False positive, no action required |
.October 20234586netty-transport-491.Finalnetty-all-4.1.79.Final.jar
| A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to execute malware which was visible to and executable by the account which booted the Derby server.
FEWS only uses embedded Derby in local Standalone-installations, embedded Derby does not support LDAP and is not accessible over a network in such configurations. Therefore this warning can safely be discarded as a false positive. | 2021 |
A vulnerability was found in the Hot Rod client provided by the Netty library. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. Netty is used by FEWS in the context of Microsoft Azure (AzureIotHub import) and THREDDS which is used by the archive server. Hot Rod is a very specific TCP client server protocol used by the Jboss Infinispan product. There is no indication of any kind that the Hot Rod protocol is used by FEWS or THREDDS in any way so this is considered a false positive warning. | 2020.02 - current | False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
26050. No .There is no indication of any kind that the Hot Rod protocol is used by FEWS or THREDDS in any way.September 2023 | 34040springboot3.0.7.jarIn Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. * The user allows untrusted sources to publish to a Kafka topic By default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record. | False positive | *.jar azure-identity-*.jar
| Azure CLI REST Command Information Disclosure Vulnerability
The Microsoft Security Response Center (MSRC) was made aware of a vulnerability where Azure Command-Line Interface (CLI) could expose sensitive information, including credentials, through GitHub Actions logs. The researcher, from Palo Alto Networks Prisma Cloud, found that Azure CLI commands could be used to show sensitive data and output to Continuous Integration and Continuous Deployment (CI/CD) logs. Microsoft recommends that customers update to the latest version of Azure CLI (2.54) and follow the guidance provided below to help prevent inadvertently exposing secrets through CI/CD logs. A notification in the Azure Portal was sent to customers who recently used Azure CLI commands informing them of an available update. | 2032.02 - current | This is a very specific use case where the role these Java libraries could play is not clear. FEWS is not using this library in the context of a CLI or Github actions so this OWASP alert is considered a false positive. | |
Jira |
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
29191False positive. No action required. Two out of three conditions mentioned in the description are not met in the case of FEWS. This library is currently only used for the admin interface, which should never be made available for use by "untrusted sources" over the internet. | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS-30236 |
---|
|
| False positive, no action required |
November 2023 | CVE-2023-36415 | azure-identity-*.jar | Azure Identity SDK Remote Code Execution Vulnerability
Above is the only information supplied
For the current 1.11.0 version we consider this a false alert for a vulnerability that needs to be addressed in the .net based Azure SDK. so it will be suppressed, specifically for CVE-2023-36415 | 2021.02 - current | False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee, |
---|
|
|
August 2023 | CVE-2023-39017 | quartz-jobs 2.3.2 | quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. This is a indirect dependency as this library is used by the THREDDS data service which is part of the archive. The source code of the current 4.6 THREDDS release has been checked to make sure that this does not use the SendQueueMessageJob class in any way so it is considered a false positive within the context of FEWS. | 2022.02 - current | False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution | columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
29689False positive. No action required. FEWS only uses this to implement OpenGIS WFS viewing capability, no server side WFS or FES implementation that could be prone to SQL injection exists in FEWS. | |
|
October 2023 | CVE-2023-45853 | zlib1.dll libz.so.1.2.13 | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.
The main author, Mark Adler states (github): Minizip is not part of zlib. The source code is provided in the contrib directory of the zlib distribution, along with several other such contributions, as a courtesy. This is not a zlib vulnerability. Additionally, zlib.def has been checked to verify that at least the windows version contains no minizip methods. | 2022 |
July 2023 | CVE-2023-35116 | jackson-databind-2.13.4.2.jar (upto 2.15.2 | ** DISPUTED ** An issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. The vulnerability concerns the Map property of the java component, not user input data and is therefore considered a false positive. It can be exploited only by reverse engineering the FEWS binaries.
| 2021.02 - current | False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
26854. No It can be exploited only by reverse engineering the FEWS binariesFebruari 25158gt264.jargt-20.0 Jira |
---|
server | Deltares Issue Tracker |
net.opengis.fes-20.0.jarThe GeoTools implementation of the OpenGIS Filter Encoding Standard (FES) has been found to contain SQL Injection Vulnerabilities when executing OGC Filters with JDBCDataStore implementations. Delft-FEWS has no such JDBCDataStore implementation and the Filter functionality has been included only to support a client side implementation of the OpenGIS WFS interface. | 2019-02 - 2022.02 | False positive | netty-all-4.1.79.Final.jar | A vulnerability was found in the Hot Rod client provided by the Netty library. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. Netty is used by FEWS in the context of Microsoft Azure (AzureIotHub import) and THREDDS which is used by the archive server. Hot Rod is a very specific TCP client server protocol used by the Jboss Infinispan product. There is no indication of any kind that the Hot Rod protocol is used by FEWS or THREDDS in any way so this is considered a false positive warning. | 2020.02 - current | False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
|
|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
27037 | False positive. No action required. |
FEWS only uses this to implement OpenGIS WFS viewing capability, no server side WFS or FES implementation that could be prone to SQL injection exists in FEWS.
|
September 2023 | CVE-2023-34040 | spring-boot-3.0.7.jar | In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: - The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record - The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. - The user allows untrusted sources to publish to a Kafka topic By default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record. Two out of three conditions mentioned in the description are not met in the case of FEWS. This library is currently only used for the admin interface, which should never be made available for use by "untrusted sources" over the internet. | 2020.02 - 2023.01 | False positive | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority, |
---|
|
|
December 2022 | CVE-2016-4432 | qpid-jms-client-0.51.0-p.jar | The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging. Delft-FEWS only uses the client, not the AMQP server. | 2021.01 - | False Positive. | Jira |
---|
server | Deltares Issue Tracker |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS-28377 |
---|
|
| False positive. No action required. Jar file can be removed from bin folder if the Azure IOT Hub import is not used. See also AzureIotHub |
Feb 2023
August 2022
CVE-2022-31197 | postgresql-42.4.1.jar postgresql-42.3.3.jar | PG 42.3.3 was flagged in Aug 2022. PG 42.4.1 was flagged only since Feb 2023. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to SQL injection. | 2022.01 - 2022.02 | False Positive. PgResultSet#refreshRow() is not used | Jira |
---|
server | Deltares Issue Tracker |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS-28737 |
---|
|
Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution | serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
27632 2022.02 and 2023.01 have been upgraded to 42.5.3.No action required.
|
Februari 2023 |
May 202220161000027springcore-5319.jarThe spring framework allows to use a http invoker that uses object serialization that may be vulnerable for Remote Code Execution. https://docs.spring.io/spring-framework/docs/current/reference/html/integration.html#remoting-httpinvoker. | 2022.01 - 2019.02 | Only used in Admin interface where the described scenario is not used. Jira |
---|
server | jar gt-20.0.jar net.opengis.fes-20.0.jar | The GeoTools implementation of the OpenGIS Filter Encoding Standard (FES) has been found to contain SQL Injection Vulnerabilities when executing OGC Filters with JDBCDataStore implementations. Delft-FEWS has no such JDBCDataStore implementation and the Filter functionality has been included only to support a client side implementation of the OpenGIS WFS interface. FEWS only uses this to implement OpenGIS WFS viewing capability, no server side WFS or FES implementation that could be prone to SQL injection exists in FEWS. | 2019-02 - 2022.02 | False positive | |
Deltares Issue Tracker | columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
27230. The HTTP Invoker method that is vulnerable is not used in any of the Delft-FEWS components. Upgrading won't help either since it won't be removed from the library. It has been marked as deprecated and will be removed in spring 6.. No action required.
|
December 2022 | CVE-2016-4432 | qpid-jms-client-0.51.0-p.jar | The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging. Delft-FEWS only uses the client, not the AMQP server. | 2021.01 - current | False Positive |
Mar 2022 | CVE-2022-26336 | poi-scratchpad 5.2 | A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1. | False positive. FEWS uses some of the Apache POI library (for the interval statistics dialog) but not the scratchpad, which is in a separate jar file. | Jira |
---|
server | Deltares Issue Tracker |
---|
|
|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS-26865 |
---|
False positive. Upgrade in development to latest release. | | serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS-28377 |
---|
|
| False positive. No action required. Jar file can be removed from bin folder if the Azure IOT Hub import is not used. See also AzureIotHub |
Feb 2023 August |
Feb 2172431197 | postgresql-42.4.1.jar postgresql-42. |
222A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. | 2021.02 - 2022.01 | PG jdbc database url manipulation enables code execution loaded via arbitrary classes. PG 42.3.3 was flagged in Aug 2022. PG 42.4.1 was flagged only since Feb 2023. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to SQL injection. | 2022.01 - 2022.02 | False Positive. PgResultSet#refreshRow() is not used | Jira |
---|
server | Deltares Issue Tracker |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
26908Upgrade to postgresql-42.3.3.jar | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key, |
---|
|
|
Nov 2021 | CVE-2021-43466 | thymeleaf-3.0.12.RELEASE.jar | In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution. Comment of Thymeleaf developer: I'd like to explain that CVE-2021-43466 only affects those applications that contain controllers or controller configurations that take a request parameter and directly use it, without previous filtering, as the name of the view to be rendered | Only used in Admin interface where the described scenario is not used. | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution | serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
26228. No action required. Once version 3.0.13 is available we can upgrade the jar to avoid this false alarm.Oct 2021 Jan . 2022.02 and 2023.01 have been upgraded to 42.5.3.
|
May 2022 | CVE- |
202142340,CVE2022-23181tomcat-embed-core-9.0.50 fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
spring framework allows to use a http invoker that uses object serialization that may be vulnerable for Remote Code Execution. https://docs.spring.io/spring-framework/docs/current/reference/html/integration.html#remoting-httpinvoker. | 2022.01 - 2019.02 | Only used in Admin interface where the described scenario is not used. | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS-27230 |
---|
|
| False positive. The HTTP Invoker method that is vulnerable is not used in any of the Delft-FEWS components. Upgrading won't help either since it won't be removed from the library. It has been marked as deprecated and will be removed in spring 6. |
Mar 2022 | CVE-2022-26336 | poi-scratchpad 5.2 | A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1. | 2021.02 only | False positive. FEWS uses some of the Apache POI library (for the interval statistics dialog) but not the scratchpad, which is in a separate jar file |
False positives. Delft-FEWS web applications don't use web sockets and doesn't use session persistence with the FileStorage. | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
26049 positives positive. Upgrade in development |
only tomcat 9 Oct 2021202137136,CVE-2021-37137
netty-all-4.1.48.Final.jar | The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack. and The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk. | False alarm. Bzip decoder is not used. Excessive memory usage might lead to a failing FSS in the worst case. Since the Azure IOT Hub is quite well secured, the risk is limited.postgresql-42.2.22.jar | A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. | 2021.02 - 2022.01 | PG jdbc database url manipulation enables code execution loaded via arbitrary classes. | Jira |
---|
server | Deltares Issue Tracker |
---|
|
|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution | serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
26050False positive. in development to latest release.to postgresql-42.3.3.jar |
Nov |
Jun 33813jdom-2.02.jar | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | Might be used in imports that use opendap. But since the library is not used in a service component, the risk is limitedthymeleaf-3.0.12.RELEASE.jar | In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution. Comment of Thymeleaf developer: I'd like to explain that CVE-2021-43466 only affects those applications that contain controllers or controller configurations that take a request parameter and directly use it, without previous filtering, as the name of the view to be rendered |
| Only used in Admin interface where the described scenario is not used. | Jira |
---|
server | Deltares Issue Tracker |
---|
columnIds | issuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
25545Dependency of ucar netcdf libraries. JDOM library has been upgraded to: jdom2-2.0.6.1.jar since 2022.01.
| False positive. No action required. Once version 3.0.13 is available we can upgrade the jar to avoid this false alarm. |
Oct 2021 Jan 2022 | CVE-2021-42340,
CVE-2022-23181 | tomcat-embed-core-9.0.50.jar | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError. The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore. | 2021.02 - 2022.02 | False positives. Delft-FEWS web applications don't use web sockets and doesn't use session persistence with the FileStorage |
Mar 2019 | CVE-2019-7611 | elasticsearch-core-6.4.3.jar | A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used | Elastic search as distributed as part of the archive server and doesn't have Field Level or Document Level Seurity disabled. As long as the provided settings are not changed, there is no risk. | Jira |
---|
server | Deltares Issue Tracker |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS-25543 |
---|
|
| False positive. No need to upgrade since the archive server configuration is correct. Once a fix is available we can upgrade the jar to avoid this false alarm. | May 2018 | CVE-2018-1258 | spring-security-core-5.4.8.jar, spring-security-oauth2-core-5.4.8.jar | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. CWE-863 Incorrect Authorization | False alarm. Spring security is used in the Admin Interface, but doesn't use version 5.0.5 of the spring framework, but a higher version. | Jira |
---|
server | Deltares Issue Tracker |
---|
columns | key,summary,type,created,updated,due,assignee,reporter,priority,status,resolution |
---|
serverId | 20635570-6a34-3a69-a785-26a57a470c5b |
---|
key | FEWS- |
---|
|
|
25865False positive. No action required. Once a fix is available we can upgrade the jar to avoid this false alarm. | ...
...
...
...