Uploaded image for project: 'Data Collection, Analytics, and Events'
  1. Data Collection, Analytics, and Events
  2. DCAEGEN2-1211

dcaegen2/collectors/hv-ves security vulnerabilities

XMLWordPrintable

      Following vulnerability identified under CLM scan; upgrade to version specified (last column)

       

       dcaegen2/collector/hv-ves  com.google.guava : guava : 19.0      Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class
      The application is vulnerable by using this component if it uses Java deserialization or GWT-RPC to deserialize untrusted data.
       Upgrade to 23.6.1-jre

            jaszczur jaszczur
            vv770d vv770d
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: