Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] Is there a plan to fix the vulnerabilities in the dependency software? #1497

Closed
1 task done
minchai23 opened this issue May 25, 2024 · 1 comment
Closed
1 task done
Labels

Comments

@minchai23
Copy link
Contributor

minchai23 commented May 25, 2024

Search before asking

  • I had searched in the issues and found no similar issues.

Question

  1. CVE-2023-39017 in Quartz 2.3.2,API misuse of org.quartz.jobs.ee.jms.SendQueueMessageJob.execute would lead the code injection vulnerability. quartz-scheduler/quartz#943
  2. Other Vulnerabilities in Spring Boot's dependent software
@lprimak
Copy link
Contributor

lprimak commented May 25, 2024

Yes. We run security scans and dependabot to keep dependencies up to date.
Currently, Security scans do not show any vulnerabilities in Shiro.

There are no current vulnerabilities listed in "Spring Boot's dependent software" that we are aware of.

I do not believe Shiro has is actually using vulnerability in the above CVE, so it doesn't really apply here.
Also, looks like Quartz scheduler is abandoned.

I am going to close this issue. Will leave your PR open under discussion in Slack

@lprimak lprimak closed this as not planned Won't fix, can't repro, duplicate, stale May 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants