Lucene search

K
ibmIBM2E24EC7A6330881A0D15BE1193C29C142E161B3A7098D958641CAEEA12C8F820
HistoryDec 14, 2020 - 2:48 p.m.

Security Bulletin: IBP javaenv and dind images

2020-12-1414:48:29
www.ibm.com
9

0.006 Low

EPSS

Percentile

79.2%

Summary

Versions of IBP images javaenv and dind before 2.5.1 included a version of gradle that depended upon vulnerable Apache libraries. Gradle is a build system, intended to aid in building chaincode, though not required for building chaincode.

Vulnerability Details

CVEID:CVE-2020-1953
**DESCRIPTION:**Apache Commons Configuration could allow a remote attacker to execute arbitrary code on the system, caused by an issue when allowing the instantiation of classes (including special statements) by default. By persuading a victim to load a specially-crafted YAML file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177759 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

**Third Party Entry:**177835
**DESCRIPTION:**Apache Commons Codec information disclosure
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177835 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Blockchain Platform (Software/on-prem) All

Remediation/Fixes

The gradle instance on the images has been replaced by a gradle ‘wrapper’ that will install the latest version of gradle.

Workarounds and Mitigations

Update Gradle, or use another build system, e.g. Maven.

0.006 Low

EPSS

Percentile

79.2%

Related for 2E24EC7A6330881A0D15BE1193C29C142E161B3A7098D958641CAEEA12C8F820