Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE in iris library #744

Open
PawelScibiorski opened this issue Jan 26, 2022 · 2 comments
Open

CVE in iris library #744

PawelScibiorski opened this issue Jan 26, 2022 · 2 comments
Assignees
Labels
prio:high This tag marks the issue as high priority and hence to be acted on at the earliest status:new This tag is attached to a new issue during creation only type:bug This tag is attached to 'bug' issue during creation

Comments

@PawelScibiorski
Copy link

Iris which is used by multiple ODIM components is vulnerable to a few CVEs

github.com/kataras/iris/v12 v12.1.8 is vulnerable to:
CVE-2021-42576 [mitre]
CVE-2021-23772 [mitre]
CVE-2021-29272 [mitre]

@Bharath-KKB Bharath-KKB added prio:high This tag marks the issue as high priority and hence to be acted on at the earliest status:new This tag is attached to a new issue during creation only type:bug This tag is attached to 'bug' issue during creation labels Mar 3, 2022
@Bharath-KKB
Copy link
Contributor

Iris which is used by multiple ODIM components is vulnerable to a few CVEs

github.com/kataras/iris/v12 v12.1.8 is vulnerable to: CVE-2021-42576 [mitre] CVE-2021-23772 [mitre] CVE-2021-29272 [mitre]

Hi Pawel many thanks for reporting this. Can you pls create issues at https://jira.lfnetworking.org/projects/ODIM/issues/ODIM-87?filter=allopenissues going forward ? We do not actively track the issues in github. You will need a LFN login for creating issues in the JIRA.

@amar-shalgar
Copy link
Contributor

This issue is resolved in ODIM services

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
prio:high This tag marks the issue as high priority and hence to be acted on at the earliest status:new This tag is attached to a new issue during creation only type:bug This tag is attached to 'bug' issue during creation
Projects
None yet
Development

No branches or pull requests

3 participants