Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(tools/quorum-all-in-one): address CVE-2021-36159 and CVE-2022-28391 #2240

Merged
merged 1 commit into from
Apr 7, 2023

Commits on Apr 6, 2023

  1. fix(tools/quorum-all-in-one): address CVE-2021-36159 and CVE-2022-28391

    Other, lower severity vulnerabilities are also being addressed by this
    change but the two big ones are the critical severity ones mentioned
    in the commit subject.
    
    Most of the vulnerabilities are now fixed in quorum-all-in-one but
    there are still some that are not because most of the remaining
    vulnerabilities are still new and is still waiting for the new changes
    to be pulled in and released on their respective package versions.
    
    And we tried to ask on the quorum discussions on github as you can
    see here. (Consensys/quorum#1513).
    
    Here are the remaining vulnerabilities for quorum-all-in-one:
    CVE-2022-3602
    CVE-2022-3786
    CVE-2022-3602
    CVE-2022-3786
    CVE-2022-42003
    CVE-2022-42004
    CVE-2022-45868
    CVE-2022-1471
    CVE-2022-21698
    CVE-2022-27664
    CVE-2022-32149
    CVE-2022-21698
    CVE-2022-27664
    CVE-2022-32149
    
    Fixes hyperledger#2059
    
    Signed-off-by: aldousalvarez <aldousss.alvarez@gmail.com>
    Signed-off-by: Peter Somogyvari <peter.somogyvari@accenture.com>
    aldousalvarez authored and petermetz committed Apr 6, 2023
    Configuration menu
    Copy the full SHA
    df6be48 View commit details
    Browse the repository at this point in the history