Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ACS AEM Common 6.3.8] Vulnerabilities Regarding Logback and Nekohtml. #3346

Open
2 tasks
glo10847 opened this issue May 27, 2024 · 1 comment
Open
2 tasks

Comments

@glo10847
Copy link

glo10847 commented May 27, 2024

Required Information

  • AEM Version/SP - 6.5.17
  • ACS AEM Commons Version: 6.3.8

Expected Behavior

No vulnerabilities regarding logback and nekohtml

Actual Behavior

Vulnerabilities found related to Logback and nekohtml in ACS AEM Commons 6.3.8

Steps to Reproduce

Customer reported vulnerabilities regarding Logback and Nekohtml. They are using AEM ACS Common OOTB Bundles. Customer ran the scan using SYNK tool.
Adobe ACS AEM Commons uses logback version 1.2.3. But as per snyk vulnerability dashboard it should upgraded to 1.2.13 or higher version due to which we are seeing above mentioned snyk vulnerabilities in the synk dashboard.

image (5) image (4) image (3)

Refer the attached Doc for more.

For vulnerabilities regarding Nekohtml , please refer the attached document.
Snyk Issues (3).docx

synk issues from acs-commons.docx

@ravrockss
Copy link

The vulnerability mentioned with logback package is still present in ACS Commons bundle 6.6.0
One pseudo fix is to exclude logback package from the codebase where acs-aem-commons-bundle is being included as a dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants