Uploaded image for project: 'JITL - JobScheduler Integrated Template Library'
  1. JITL - JobScheduler Integrated Template Library
  2. JITL-714

JS1 and JS7 KeePass CredentialStore Interface should not use vulnerable 3rd-party library simple-xml (CVE-2017-1000190, CVE-2017-14868)

    XMLWordPrintable

Details

    • Feature
    • Status: Released (View Workflow)
    • Major
    • Resolution: Fixed
    • 1.13.0, 2.0.0
    • 1.13.19, 2.5.4, 2.6.0
    • None
    • CVE-2017-1000190, CVE-2017-14868

    Description

      Current Situation.

      • Vulnerabilities
        • The simple-xml (org.simpleframework) 3rd-party library is subject to the vulnerabilities CVE-2017-1000190 and CVE-2017-14868
        • No active development or support for the 3rd-party library can be observed. As a result at the time of writing no fixed version is available.
      • Risk Mitigation
        • The library is used for access to a KeePass Credential Store in JS7 Agents. A direct exploit cannot be observed.
        • However, due to the fact that the library is used for access to secrets it is not recommended to continue use of the library.
        • Users can remove the library if they do not make use of the Credential Store feature. For details how to remove this feature see JS7 - Package Management

      Desired Behavior

      • SOS removes the library from future releases and implements a replacement.

      Test Instructions

      Attachments

        Issue Links

          Activity

            People

              re Robert Ehrlich
              re Robert Ehrlich
              Pramokshi Narawariya Pramokshi Narawariya
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: