JFrog Security Fixed Security Vulnerabilities

CVEs Impacting Xray

The following is a list of CVEs that were discovered to impact Xray and were fixed.

CVESeverityXray Fix VersionFix Description
CVE-2022-31030Medium3.60.2Upgraded github.com/containerd/containerd version to 1.5.13.
CVE-2022-28948High3.60.2Upgraded gopkg.in/yaml.v3:3.0.0-20200313102051 version to gopkg.in/yaml.v3:3.0.1.
CVE-2022-27664High

3.60.2

3.61.5

Upgraded golang.org/x/net v0.0.0-20220722155237 to golang.org/x/net version 0.1.0

Upgraded golang.org/x/sys v0.0.0-20220722155237 to golang.org/x/sys v0.1.0

Upgraded golang.org/x/net v0.3.7 to golang.org/x/text v0.4.0.

CVE-2022-32149High3.60.2Upgraded from 0.3.7 to 0.3.8.
CVE-2022-32189High3.59.4Upgraded Golang version to 1.18.5.
CVE-2021-38197Critical3.57.6Upgraded go-unarr library to version v0.1.4.
CVE-2022-29526Medium3.55.2Upgraded Golang version to 1.18.4.
CVE-2022-30634High3.55.2Upgraded Golang version to 1.18.4.
CVE-2022-30632High3.55.2Upgraded Golang version to 1.18.4.
CVE-2022-30630High3.55.2Upgraded Golang version to 1.18.4.
CVE-2022-30631High3.55.2Upgraded Golang version to 1.18.4.
CVE-2022-24769Medium3.54.5Upgraded Containerd version to 1.5.11.
CVE-2022-29526Medium3.54.5Upgraded to Golang version to 1.17.11.
CVE-2022-23806Critical3.50.3Upgraded JFrog router version to 7.39.0.
CVE-2022-27191High3.49.0Upgraded golang.org/x/cryptoto v0.0.0-20220314234659-1baeb1ce4c0.
CVE-2022-24675High3.48.2Upgraded Golang version to 1.17.9.
CVE-2022-24921High3.48.2Upgraded Golang version to 1.17.9.
CVE-2021-43816Critical3.42.3Upgraded Containerd version to 1.5.9.
CVE-2021-44717Medium3.41.4Upgraded Golang version to 1.17.5.
CVE-2021-44716High3.41.4Upgraded Golang version to 1.17.5.
CVE-2021-41771High3.38.1Upgraded Golang version to 1.17.3.
CVE-2021-33196High3.34.1Upgraded Golang version to 1.15.13, 1.16.5.

CVEs Not Impacting Xray

The following is a list of CVEs that do not impact Xray.

CVESeverityXray Fix VersionFix Description
CVE-2021-38197Critical3.57.6Upgraded go-unarr library to version v0.1.4.
CVE-2025-22871Critical3.103.x and up

Not applicable.

The vulnerable functions (net/http.ListenAndServe, net/http.ListenAndServeTLS, net/http.Serve, net/http.ServeTLS, net/http.Server.ListenAndServe, net/http.Server.ListenAndServeTLS, net/http.Server.Serve ) are never called. The Xray application does not utilize the affected functions, making exploitation impossible.

CVE-2024-34156High3.103.x and up

Not applicable.

The vulnerable functions (encoding/gob/Decoder.Decode, encoding/gob/Decoder.DecodeValue) are never called. The Xray application does not utilize the affected functions, making exploitation impossible.

CVE-2019-17543Medium3.103.x and up

Not applicable.

The vulnerability is only applicable if one of the vulnerable functions (LZ4_compress, LZ4_compress_limitedOutput, LZ4_compress_default, LZ4_compress_fast) is called. The Xray application does not utilize the affected functions, making exploitation impossible.

CVE-2024-10979High3.107.x and up

Not applicable.

The vulnerable PostgreSQL application is not compiled with perl extension (plperl).

CVE-2024-34158High3.107.x and up

Not applicable.

The vulnerable function go/build/constraint.Parseis never called. The Xray application does not utilize the affected function, making exploitation impossible


Did this page help you?