operatorfabric-core
operatorfabric-core copied to clipboard
CVE-2023-50572 (Medium) detected in jline-3.22.0.jar
CVE-2023-50572 - Medium Severity Vulnerability
Vulnerable Library - jline-3.22.0.jar
Path to dependency file: /src/test/gatling/gatlingTests.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.jline/jline/3.22.0/512dde71f1ba9cb87f318e4e1e3acc77dc67a712/jline-3.22.0.jar
Dependency Hierarchy:
- zinc_2.13-1.9.3.jar (Root Library)
- zinc-compile-core_2.13-1.9.3.jar
- zinc-classpath_2.13-1.9.3.jar
- scala-compiler-2.13.11.jar
- :x: jline-3.22.0.jar (Vulnerable Library)
- scala-compiler-2.13.11.jar
- zinc-classpath_2.13-1.9.3.jar
- zinc-compile-core_2.13-1.9.3.jar
Found in HEAD commit: 618b3c3a2d5e3ed5d1a5d21480c82309130389a5
Found in base branch: develop
Vulnerability Details
An issue in the component GroovyEngine.execute of jline-groovy v3.24.1 allows attackers to cause an OOM (OutofMemory) error.
Publish Date: 2023-12-29
URL: CVE-2023-50572
CVSS 3 Score Details (5.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Release Date: 2023-12-29
Fix Resolution: org.jline:jline-console:3.25.0,org.jline:jline:3.25.0
Step up your Open Source Security Game with Mend here