Skip to content

Commit

Permalink
chore: file advisories for management-api-for-apache-cassandra-5.0 (#…
Browse files Browse the repository at this point in the history
…8713)

Signed-off-by: Mritunjay <[email protected]>
  • Loading branch information
mritunjaysharma394 authored Oct 18, 2024
1 parent 63b20d4 commit 40dde40
Showing 1 changed file with 52 additions and 0 deletions.
52 changes: 52 additions & 0 deletions management-api-for-apache-cassandra-5.0.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:15:03Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.0'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-5jp4-3j6v-xcj7
aliases:
Expand All @@ -39,6 +43,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:22:40Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.10'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-654j-wjm3-qmg4
aliases:
Expand All @@ -57,6 +65,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T15:22:40Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''classgraph'' to ''4.8.112'' or later but this fix will require some code changes on the upstream repository.'

- id: CGA-85g9-6hwh-32gx
aliases:
Expand All @@ -75,6 +87,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:22:20Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade swagger-jaxrs2'' to ''2.2.10'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-9gmq-c996-778j
aliases:
Expand All @@ -93,6 +109,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T15:24:57Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.0'' or later but this fix will require some code change since the upgrade cause the build to fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-c8q6-4qp3-vqhh
aliases:
Expand All @@ -111,6 +131,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:15:11Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.0'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-hrp6-hg6x-533q
aliases:
Expand All @@ -129,6 +153,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:22:10Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.10'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-mhgw-xcxh-mprj
aliases:
Expand All @@ -147,6 +175,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:25:44Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.11'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-pc67-qgg2-hpmq
aliases:
Expand All @@ -165,6 +197,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:22:30Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.10'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-v95v-8w2m-8jvx
aliases:
Expand All @@ -183,6 +219,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:14:57Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.0'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-vgwv-c777-jqwv
aliases:
Expand All @@ -201,6 +241,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:26:02Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.10'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

- id: CGA-vppp-hq87-2m8x
aliases:
Expand All @@ -219,6 +263,10 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T16:02:18Z
type: pending-upstream-fix
data:
note: Commons-io v2.9.0 is a transitive dependency that is brought in under the resteasy-client-api, even the most up to date version of the 4.x.x version stream (4.7.9) contains the affected version of commons-io. This requires the upstream maintainers to implement a fix.

- id: CGA-w753-xwwq-8ch4
aliases:
Expand All @@ -237,3 +285,7 @@ advisories:
componentType: java-archive
componentLocation: /opt/management-api/datastax-mgmtapi-server-0.1.0-SNAPSHOT.jar
scanner: grype
- timestamp: 2024-10-18T18:21:41Z
type: pending-upstream-fix
data:
note: 'To fix the CVE, we have to upgrade ''swagger-jaxrs2'' to ''2.2.10'' or later but this fix will require some code change since the upgrade cause to build fail due to compilation errors like: ''src/main/java/com/datastax/mgmtapi/resources/LifecycleResources.java:[425,28] cannot access com.fasterxml.jackson.core.exc.StreamWriteException'''

0 comments on commit 40dde40

Please sign in to comment.