Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable dependency xmlrpc-common-3.1.3.jar: CVE-2016-5002 #48

Open
concernedrat opened this issue Dec 14, 2017 · 2 comments
Open

Vulnerable dependency xmlrpc-common-3.1.3.jar: CVE-2016-5002 #48

concernedrat opened this issue Dec 14, 2017 · 2 comments

Comments

@concernedrat
Copy link
Contributor

concernedrat commented Dec 14, 2017

A quick security check on the dependencies thrown a high (CVSS >= 8) for xmlrpc-common.

I will submit a patch (major update) to this project to swap the xmlrpc client for a non-vulnerable xmlrpc client

@concernedrat concernedrat changed the title xmlrpc-common-3.1.3.jar: CVE-2016-5002 Vulnerable dependency xmlrpc-common-3.1.3.jar: CVE-2016-5002 Dec 14, 2017
@concernedrat
Copy link
Contributor Author

Planning to use this lib:

https://github.com/gturri/aXMLRPC

Any suggestions are greatly appreciated.

@flotho
Copy link
Collaborator

flotho commented Jan 20, 2018

Hi @georgerb ,
Thanks for your proposal.
This point has been pointed out by Pentaho Team #43 .
So great idea.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants