Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[6.1.2] vulnerable dependency org.apache.velocity:velocity-engine-core@2.2 with CVE-2020-13936 #3205

Closed
albuch opened this issue Mar 19, 2021 · 2 comments
Labels
Milestone

Comments

@albuch
Copy link
Contributor

albuch commented Mar 19, 2021

Describe the bug
dependency-check-core v6.1.2 contains a vulnerable dependency org.apache.velocity:velocity-engine-core@2.2 with CVE-2020-13936

Version of dependency-check used
dependency-check-core:6.1.2

@albuch albuch added the bug label Mar 19, 2021
@albuch
Copy link
Contributor Author

albuch commented Mar 19, 2021

I see this is already updated in the current snapshot via #3181, however I'm not sure if this warrants a rather quick release? What's your take on this @jeremylong?

@jeremylong
Copy link
Owner

From the CVE "An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container.'... I'm just not sure the attack path is there for 99.9% of the use cases for ODC...

However, I also know the zero tolerance some have for known vulnerable libraries... So I suppose we should release 6.1.3.

@jeremylong jeremylong added this to the 6.1.3 milestone Mar 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants