Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
2.5.3
-
None
-
None
-
CVE-2020-8908, CVE-2023-2976
Description
Current Situation
- Currently JS7 Controller, Agent and JOC Cockpit make use of guava version 31.1-jre
- two vulnerabilities affect this version,
- see https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-8908
- we rate the impact of this vulnerability as low, as our software does not make use of Guavas createTempDir implementation
- see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2976
- we haven´t rated this issue yet, as the vulnerability description has not been made public as of the moment
- see https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-8908
Desired Behavior
- Due to a vulnerability Issue of older guava releases JS7 should use the current version 32.0.1-jre that fixes the issues.