You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@activemq.apache.org by "Felix Knecht (Jira)" <ji...@apache.org> on 2022/09/07 14:21:00 UTC

[jira] [Commented] (AMQ-8984) Fix or challenge CVE-2015-3208 reported by ossindex.sonatype.org

    [ https://issues.apache.org/jira/browse/AMQ-8984?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17601332#comment-17601332 ] 

Felix Knecht commented on AMQ-8984:
-----------------------------------

Sonatype Deep Dive research seems to have determined that this is still an issue: [https://github.com/OSSIndex/vulns/issues/307|https://github.com/OSSIndex/vulns/issues/307]

> Fix or challenge CVE-2015-3208 reported by ossindex.sonatype.org
> ----------------------------------------------------------------
>
>                 Key: AMQ-8984
>                 URL: https://issues.apache.org/jira/browse/AMQ-8984
>             Project: ActiveMQ
>          Issue Type: Bug
>          Components: Broker
>    Affects Versions: 5.16.3, 5.16.4, 5.16.5
>            Reporter: Sven-Jørgen Karlsen
>            Assignee: Jean-Baptiste Onofré
>            Priority: Minor
>
> I get CVE-2015-3208 reported against activemq-broker 5.16.3-5 when running maven-enforcer-plugin with the banVulnerable rule. The vulnerability can also be seen on ossindex.org: [https://ossindex.sonatype.org/vulnerability/CVE-2015-3208?component-type=maven&component-name=org.apache.activemq%2Factivemq-broker&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1]
>  
> It looks rather dated, is it some kind of fault in Sonatype's database? I have seen several odd occurrences of old vulnerabilities in ossindex.org the last month or so, after the "breaking changes" being working on in the OSS Index data.
>  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)