Uploaded image for project: 'JOC - JS7 Operations Center'
  1. JOC - JS7 Operations Center
  2. JOC-2020

Update eddsa version 0.3.0 due to 3rd Party Vulnerability issue CVE-2020-36843

    XMLWordPrintable

Details

    • Fix
    • Status: Released (View Workflow)
    • Minor
    • Resolution: Fixed
    • 2.5.11, 2.7.3, 2.8.0
    • 2.5.12, 2.7.6, 2.8.1
    • None
    • None
    • CVE-2020-36843

    Description

      Current Situation

      • JS7 JOC Cockpit and Agent ship with 3rd party library eddsa 0.3.0 through the use of 3rd party library sshj.
      • a vulnerability affects this version, see https://nvd.nist.gov/vuln/detail/CVE-2020-36843
      • no newer version of eddsa is available at the time, which fixes the problem

      Findings

      • a fix from a different publisher is available since march 2019

      Attachments

        Activity

          People

            sp Santiago Aucejo Petzoldt
            sp Santiago Aucejo Petzoldt
            Ajay Kumbhkar Ajay Kumbhkar
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: