Uploaded image for project: 'JOC - JobScheduler Operations Center'
  1. JOC - JobScheduler Operations Center
  2. JOC-1623

Update commons-compress to version 1.24.0 due to 3rd-party vulnerability issue

    XMLWordPrintable

Details

    • Fix
    • Status: Released (View Workflow)
    • Minor
    • Resolution: Fixed
    • 2.5.5, 2.6.2
    • 2.5.6, 2.6.3
    • None
    • None
    • CVE-2023-42503

    Description

      Current Situation

      Impact

      We rate the impact to our software as low as our implementation does not make use of the combination of classes to read files from a filesystem.

      Desired Behavior

      JS7 Agent and JOC Cockpit should use the latest version 1.24.0 of commons-compress which fixes the vulnerability.

      Attachments

        Activity

          People

            sp Santiago Aucejo Petzoldt
            sp Santiago Aucejo Petzoldt
            Kanika Agrawal Kanika Agrawal
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: