-
Notifications
You must be signed in to change notification settings - Fork 72
/
Copy pathcassandra-4.1.advisories.yaml
144 lines (136 loc) · 4.81 KB
/
cassandra-4.1.advisories.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
schema-version: 2.0.2
package:
name: cassandra-4.1
advisories:
- id: CGA-334h-ff83-4pcg
aliases:
- CVE-2023-6378
- GHSA-vmq6-5m68-f53m
events:
- timestamp: 2024-02-27T07:15:10Z
type: detection
data:
type: scan/v1
data:
subpackageName: cassandra-4.1
componentID: 98c4965ba337dd57
componentName: logback-classic
componentVersion: 1.2.9
componentType: java-archive
componentLocation: /usr/share/java/cassandra/lib/logback-classic-1.2.9.jar
scanner: grype
- timestamp: 2024-02-27T07:17:10Z
type: false-positive-determination
data:
type: vulnerable-code-version-not-used
note: 'CVE considered a false positive by the maintainers since Cassandra doesn''t ship logback in a remote configuration: https://issues.apache.org/jira/browse/CASSANDRA-19142'
- id: CGA-4c23-wq8x-6jp3
aliases:
- CVE-2024-12801
- GHSA-6v67-2wr5-gvf4
events:
- timestamp: 2025-03-04T18:28:52Z
type: detection
data:
type: scan/v1
data:
subpackageName: cassandra-4.1
componentID: 323fea64988dd390
componentName: logback-core
componentVersion: 1.2.9
componentType: java-archive
componentLocation: /usr/share/java/cassandra/lib/logback-core-1.2.9.jar
scanner: grype
- id: CGA-6p73-mwqp-2hp8
aliases:
- CVE-2023-2976
- GHSA-7g45-4rm6-3mm3
events:
- timestamp: 2024-02-27T07:15:09Z
type: detection
data:
type: scan/v1
data:
subpackageName: cassandra-4.1
componentID: f069ff97983ab311
componentName: guava
componentVersion: 27.0-jre
componentType: java-archive
componentLocation: /usr/share/java/cassandra/lib/guava-27.0-jre.jar
scanner: grype
- timestamp: 2024-02-27T07:17:10Z
type: false-positive-determination
data:
type: vulnerability-record-analysis-contested
note: 'CVE considered a false positive by the maintainers: https://github.com/apache/cassandra/blob/cassandra-4.1/.build/dependency-check-suppressions.xml'
- id: CGA-7w78-ggr5-pfxv
aliases:
- CVE-2022-1471
- GHSA-mjmj-j48q-9wg2
events:
- timestamp: 2024-02-27T07:15:10Z
type: detection
data:
type: scan/v1
data:
subpackageName: cassandra-4.1
componentID: 300a4a1a14f08cef
componentName: snakeyaml
componentVersion: "1.32"
componentType: java-archive
componentLocation: /usr/share/java/cassandra/lib/snakeyaml-1.32.jar
scanner: grype
- timestamp: 2024-02-27T07:17:10Z
type: false-positive-determination
data:
type: vulnerable-code-cannot-be-controlled-by-adversary
note: 'CVE considered a false positive by the maintainers: https://github.com/apache/cassandra/blob/cassandra-4.1/.build/dependency-check-suppressions.xml'
- id: CGA-c2qf-hfph-rrp7
aliases:
- CVE-2020-13946
- GHSA-24ww-mc5x-xc43
events:
- timestamp: 2024-02-27T07:17:09Z
type: false-positive-determination
data:
type: vulnerable-code-version-not-used
note: Vulnerable cocode was fixed in Cassandra 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2. Earliest Wolfi package is 4.1.3
- id: CGA-f85c-8jfc-2g85
aliases:
- CVE-2020-8908
- GHSA-5mg8-w23w-74h3
events:
- timestamp: 2024-02-27T07:15:09Z
type: detection
data:
type: scan/v1
data:
subpackageName: cassandra-4.1
componentID: f069ff97983ab311
componentName: guava
componentVersion: 27.0-jre
componentType: java-archive
componentLocation: /usr/share/java/cassandra/lib/guava-27.0-jre.jar
scanner: grype
- timestamp: 2024-02-27T07:17:09Z
type: false-positive-determination
data:
type: vulnerability-record-analysis-contested
note: 'CVE considered a false positive by the maintainers: https://github.com/apache/cassandra/blob/cassandra-4.1/.build/dependency-check-suppressions.xml'
- id: CGA-mr25-gp63-63ff
aliases:
- CVE-2024-12798
- GHSA-pr98-23f8-jwxv
events:
- timestamp: 2025-03-04T18:28:55Z
type: detection
data:
type: scan/v1
data:
subpackageName: cassandra-4.1
componentID: 323fea64988dd390
componentName: logback-core
componentVersion: 1.2.9
componentType: java-archive
componentLocation: /usr/share/java/cassandra/lib/logback-core-1.2.9.jar
scanner: grype