Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BlackDuck scan reports vulnerabilities in PCRE2 which is referenced by Microsoft.Azure.Cosmos.ServiceInterop #4685

Open
abhishekdurvasula opened this issue Sep 13, 2024 · 3 comments
Assignees
Labels

Comments

@abhishekdurvasula
Copy link

abhishekdurvasula commented Sep 13, 2024

BlackDuck scan reports vulnerabilities in the PCRE2 component. This component is reference by Microsoft.Azure.Cosmos.ServiceInterop.dll
The version of Microsoft.Azure.Cosmos.ServiceInterop.dll is 2.14
image

We are using Microsoft.Azure.Cosmos v3.43.0 NuGet Package.

Below are the Black Duck issues reported:

  1. CVE-2022-1586
  2. CVE-2022-1587
  3. CVE-2022-41409

According to discussion in this issue, the first two vulnerabilities don't apply as PCRE is not used with JIT enabled.

The version of PCRE2 being used is still 10.34. I have gotten this information from ThirdPartyNotice.txt on the Microsoft.Azure.Cosmos.Direct package as mentioned in above issue. Black Duck suggests that 10.44 doesn't have any vulnerabilities.

Can we get an update on the 3rd issue if the version of PCRE2 can't be upgraded?

@kirankumarkolli
Copy link
Member

@adityasa can you please take alook?

@adityasa adityasa assigned neildsh and unassigned adityasa Sep 16, 2024
@adityasa
Copy link
Contributor

adityasa commented Sep 16, 2024

Hey @neildsh, can you help look into this issue?

@abhishekdurvasula
Copy link
Author

Hello. Is there any update on this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants