|
1 | 1 | { |
2 | 2 | "vcs_url": "https://github.com/apache/activemq", |
3 | 3 | "vulnerabilities": { |
| 4 | + "CVE-2026-47323": { |
| 5 | + "09a74c5fb9b582ff300130c4696ab559f54bb822": "Bump dependencies for CVE fixes on 6.2.x (#2030)\n\n- camel 4.14.4 -> 4.14.7 (CVE-2026-47323, CVE-2026-27172, CVE-2026-28367)\n- jolokia 2.5.0 -> 2.6.0\n- snappy 1.1.2 -> 1.1.10.7 (CVE-2023-34455, CVE-2023-43642)\n- spring 6.2.16 -> 6.2.18" |
| 6 | + }, |
| 7 | + "CVE-2026-27172": { |
| 8 | + "09a74c5fb9b582ff300130c4696ab559f54bb822": "Bump dependencies for CVE fixes on 6.2.x (#2030)\n\n- camel 4.14.4 -> 4.14.7 (CVE-2026-47323, CVE-2026-27172, CVE-2026-28367)\n- jolokia 2.5.0 -> 2.6.0\n- snappy 1.1.2 -> 1.1.10.7 (CVE-2023-34455, CVE-2023-43642)\n- spring 6.2.16 -> 6.2.18" |
| 9 | + }, |
| 10 | + "CVE-2026-28367": { |
| 11 | + "09a74c5fb9b582ff300130c4696ab559f54bb822": "Bump dependencies for CVE fixes on 6.2.x (#2030)\n\n- camel 4.14.4 -> 4.14.7 (CVE-2026-47323, CVE-2026-27172, CVE-2026-28367)\n- jolokia 2.5.0 -> 2.6.0\n- snappy 1.1.2 -> 1.1.10.7 (CVE-2023-34455, CVE-2023-43642)\n- spring 6.2.16 -> 6.2.18" |
| 12 | + }, |
| 13 | + "CVE-2023-34455": { |
| 14 | + "09a74c5fb9b582ff300130c4696ab559f54bb822": "Bump dependencies for CVE fixes on 6.2.x (#2030)\n\n- camel 4.14.4 -> 4.14.7 (CVE-2026-47323, CVE-2026-27172, CVE-2026-28367)\n- jolokia 2.5.0 -> 2.6.0\n- snappy 1.1.2 -> 1.1.10.7 (CVE-2023-34455, CVE-2023-43642)\n- spring 6.2.16 -> 6.2.18" |
| 15 | + }, |
| 16 | + "CVE-2023-43642": { |
| 17 | + "09a74c5fb9b582ff300130c4696ab559f54bb822": "Bump dependencies for CVE fixes on 6.2.x (#2030)\n\n- camel 4.14.4 -> 4.14.7 (CVE-2026-47323, CVE-2026-27172, CVE-2026-28367)\n- jolokia 2.5.0 -> 2.6.0\n- snappy 1.1.2 -> 1.1.10.7 (CVE-2023-34455, CVE-2023-43642)\n- spring 6.2.16 -> 6.2.18", |
| 18 | + "647d31844e416478234cbbd14f442ee7ee32d273": "Bump dependencies to address known CVEs (#2031)\n\n- netty 4.1.94.Final -> 4.1.133.Final (CVE-2024-29025, CVE-2025-58057, SslHandler native crash patched in 4.1.118.Final)\n- snappy 1.1.2 -> 1.1.10.8 (CVE-2023-34453/34454/34455, CVE-2023-43642)\n- karaf 4.3.7 -> 4.3.10 (CVE-2022-40145 JNDI LDAP RCE)" |
| 19 | + }, |
| 20 | + "CVE-2024-29025": { |
| 21 | + "647d31844e416478234cbbd14f442ee7ee32d273": "Bump dependencies to address known CVEs (#2031)\n\n- netty 4.1.94.Final -> 4.1.133.Final (CVE-2024-29025, CVE-2025-58057, SslHandler native crash patched in 4.1.118.Final)\n- snappy 1.1.2 -> 1.1.10.8 (CVE-2023-34453/34454/34455, CVE-2023-43642)\n- karaf 4.3.7 -> 4.3.10 (CVE-2022-40145 JNDI LDAP RCE)" |
| 22 | + }, |
| 23 | + "CVE-2025-58057": { |
| 24 | + "647d31844e416478234cbbd14f442ee7ee32d273": "Bump dependencies to address known CVEs (#2031)\n\n- netty 4.1.94.Final -> 4.1.133.Final (CVE-2024-29025, CVE-2025-58057, SslHandler native crash patched in 4.1.118.Final)\n- snappy 1.1.2 -> 1.1.10.8 (CVE-2023-34453/34454/34455, CVE-2023-43642)\n- karaf 4.3.7 -> 4.3.10 (CVE-2022-40145 JNDI LDAP RCE)" |
| 25 | + }, |
| 26 | + "CVE-2023-34453": { |
| 27 | + "647d31844e416478234cbbd14f442ee7ee32d273": "Bump dependencies to address known CVEs (#2031)\n\n- netty 4.1.94.Final -> 4.1.133.Final (CVE-2024-29025, CVE-2025-58057, SslHandler native crash patched in 4.1.118.Final)\n- snappy 1.1.2 -> 1.1.10.8 (CVE-2023-34453/34454/34455, CVE-2023-43642)\n- karaf 4.3.7 -> 4.3.10 (CVE-2022-40145 JNDI LDAP RCE)" |
| 28 | + }, |
| 29 | + "CVE-2022-40145": { |
| 30 | + "647d31844e416478234cbbd14f442ee7ee32d273": "Bump dependencies to address known CVEs (#2031)\n\n- netty 4.1.94.Final -> 4.1.133.Final (CVE-2024-29025, CVE-2025-58057, SslHandler native crash patched in 4.1.118.Final)\n- snappy 1.1.2 -> 1.1.10.8 (CVE-2023-34453/34454/34455, CVE-2023-43642)\n- karaf 4.3.7 -> 4.3.10 (CVE-2022-40145 JNDI LDAP RCE)" |
| 31 | + }, |
4 | 32 | "CVE-2022-23437": { |
5 | 33 | "25b20550271a7208e5c91557b5b84db87e32be1d": "AMQ-8648 - CVE-2022-23437: Infinite loop within Apache XercesJ xml parser\n\n(cherry picked from commit 70915ea5c078d796a81be7d0d2b511330fd150d4)", |
6 | 34 | "b572d0cd5a2cdf818d4cf4ce8507d0fec6b1cf65": "AMQ-8648 - CVE-2022-23437: Infinite loop within Apache XercesJ xml parser\n\n(cherry picked from commit 70915ea5c078d796a81be7d0d2b511330fd150d4)", |
|
0 commit comments