Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE issues #680

Closed
pchao00 opened this issue Aug 19, 2022 · 3 comments
Closed

CVE issues #680

pchao00 opened this issue Aug 19, 2022 · 3 comments

Comments

@pchao00
Copy link

pchao00 commented Aug 19, 2022

using dependency-check still have following security issues:
CVE-2018-1000538](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1000538)
CVE-2020-11012](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11012)

@harshavardhana
Copy link
Member

This issue doesn't make sense - what is it that you want to ask @pchao00 ?

@ebozduman
Copy link
Collaborator

ebozduman commented Oct 10, 2022

First of all, these 2 vulnerabilities were in minio, but not in minio-dotnet. This issue should have been filed against Minio repo.

Yet again, these 2 vulnerabilities have been already addressed in minio repo :

CVE-2018-1000538] is addressed on May 18th 2018 with minio PR#5957 and the fix became available in RELEASE.2018-05-25T19-49-13Z.

CVE-2020-11012 is addressed on Apr 22 2020 with minio PR#9422 and the fix became available in RELEASE.2020-04-23T00-58-49Z

@pchao00
I ran the dependency check and did not see anything in the generated report.

So, you need to give us more information:
What was the version of the MinIO server you ran the dependency check on?
What was/is your platform/OS?
Could you please also explain what exact command/s you used to initiate the dependency check?
Basically we want to know how to reproduce these 2 dependency check failures.
Please also attach the generated dependency check report, if you can.

@ebozduman
Copy link
Collaborator

Closing the issue as there is no response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants