[jira] [Commented] (CASSANDRA-15423) CVE-2015-2156 (Netty is vulnerable to Information Disclosure)

2019-11-14 Thread Abhishek Singh (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-15423?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16974783#comment-16974783 ] Abhishek Singh commented on CASSANDRA-15423: Thanks Dinesh. I took a note of it. >

[jira] [Created] (CASSANDRA-15425) sonatype-2013-0069 (The setuptools package is vulnerable to Directory Traversal)

2019-11-13 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15425: -- Summary: sonatype-2013-0069 (The setuptools package is vulnerable to Directory Traversal) Key: CASSANDRA-15425 URL:

[jira] [Created] (CASSANDRA-15424) CVE-2018-1320 (The libthrift component is vulnerable to Improper Access Control)

2019-11-13 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15424: -- Summary: CVE-2018-1320 (The libthrift component is vulnerable to Improper Access Control) Key: CASSANDRA-15424 URL:

[jira] [Created] (CASSANDRA-15423) CVE-2015-2156 (Netty is vulnerable to Information Disclosure)

2019-11-13 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15423: -- Summary: CVE-2015-2156 (Netty is vulnerable to Information Disclosure) Key: CASSANDRA-15423 URL: https://issues.apache.org/jira/browse/CASSANDRA-15423

[jira] [Created] (CASSANDRA-15422) CVE-2018-1320(The libthrift component is vulnerable to Improper Access Control) on Cassendra 3.11.4

2019-11-13 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15422: -- Summary: CVE-2018-1320(The libthrift component is vulnerable to Improper Access Control) on Cassendra 3.11.4 Key: CASSANDRA-15422 URL:

[jira] [Created] (CASSANDRA-15421) CVE-2017-5929(QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.)

2019-11-13 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15421: -- Summary: CVE-2017-5929(QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.) Key: CASSANDRA-15421

[jira] [Created] (CASSANDRA-15420) CVE-2019-0205(Apache Thrift all versions up to and including 0.12.0) on version Cassendra 3.11.4

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15420: -- Summary: CVE-2019-0205(Apache Thrift all versions up to and including 0.12.0) on version Cassendra 3.11.4 Key: CASSANDRA-15420 URL:

[jira] [Created] (CASSANDRA-15419) sonatype-2013-0069(The setuptools package is vulnerable to Directory Traversal) on Cassendra 3.11.4

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15419: -- Summary: sonatype-2013-0069(The setuptools package is vulnerable to Directory Traversal) on Cassendra 3.11.4 Key: CASSANDRA-15419 URL:

[jira] [Created] (CASSANDRA-15418) CVE-2019-16869(Netty is vulnerable to HTTP Request Smuggling) of severity 7.5 for Cassendra 2.2.5

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15418: -- Summary: CVE-2019-16869(Netty is vulnerable to HTTP Request Smuggling) of severity 7.5 for Cassendra 2.2.5 Key: CASSANDRA-15418 URL:

[jira] [Created] (CASSANDRA-15417) CVE-2019-16869(Netty is vulnerable to HTTP Request Smuggling) of severity 7.5

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15417: -- Summary: CVE-2019-16869(Netty is vulnerable to HTTP Request Smuggling) of severity 7.5 Key: CASSANDRA-15417 URL: https://issues.apache.org/jira/browse/CASSANDRA-15417

[jira] [Created] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15416: -- Summary: CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4 Key: CASSANDRA-15416 URL:

[jira] [Created] (CASSANDRA-15415) CVE-2019-0205 (Apache Thrift all versions up to and including 0.12.0 vulnerable) of severity 7.5

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15415: -- Summary: CVE-2019-0205 (Apache Thrift all versions up to and including 0.12.0 vulnerable) of severity 7.5 Key: CASSANDRA-15415 URL:

[jira] [Created] (CASSANDRA-15414) sonatype-2018-0119 (Netty is vulnerable to a Denial of Service (DoS) attack)

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15414: -- Summary: sonatype-2018-0119 (Netty is vulnerable to a Denial of Service (DoS) attack) Key: CASSANDRA-15414 URL: https://issues.apache.org/jira/browse/CASSANDRA-15414

[jira] [Created] (CASSANDRA-15412) Security vulnerability CVE-2016-4970 for Netty

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15412: -- Summary: Security vulnerability CVE-2016-4970 for Netty Key: CASSANDRA-15412 URL: https://issues.apache.org/jira/browse/CASSANDRA-15412 Project:

[jira] [Updated] (CASSANDRA-15411) [9.8] [CVE-2017-5929] [Cassandra] [2.2.5]

2019-11-12 Thread Abhishek Singh (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-15411?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Abhishek Singh updated CASSANDRA-15411: --- Description: *Description :**Description :* *Severity :* CVE CVSS 3.0:

[jira] [Created] (CASSANDRA-15411) [9.8] [CVE-2017-5929] [Cassandra] [2.2.5]

2019-11-12 Thread Abhishek Singh (Jira)
Abhishek Singh created CASSANDRA-15411: -- Summary: [9.8] [CVE-2017-5929] [Cassandra] [2.2.5] Key: CASSANDRA-15411 URL: https://issues.apache.org/jira/browse/CASSANDRA-15411 Project: Cassandra

[jira] [Assigned] (CASSANDRA-15410) Avoid over-allocation of bytes for UTF8 string serialization

2019-11-12 Thread Abhishek Singh (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-15410?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Abhishek Singh reassigned CASSANDRA-15410: -- Assignee: Abhishek Singh (was: Yifan Cai) > Avoid over-allocation of