Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document non-exploitability of CVE-2023-5129 #130

Merged
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 15 additions & 2 deletions security.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,21 @@ mailing list of the [ASF Security Team](https://www.apache.org/security/) or
the <[email protected]> mailing list, before disclosing or
discussing the issue in a public forum.

Is Apache Guacamole affected by CVE-2021-44228? {#not-affected-by-cve-2021-44228}
-----------------------------------------------
Vulnerabilities in dependencies
-------------------------------

### Is Apache Guacamole affected by CVE-2023-5129? {#not-affected-by-cve-2023-5129}

No. CVE-2023-5129 (aka CVE-2023-4863) deals specifically with decoding
WebP images, not encoding.

You would also receive updates to libwebp from your distribution as the
library itself is not bundled within Guacamole. If using our Docker
images, the images are automatically rebuilt nightly to bring in updates
from the maintainer of the base image (Alpine Linux), and a pull of the
latest would give you an updated image.

### Is Apache Guacamole affected by CVE-2021-44228? {#not-affected-by-cve-2021-44228}

No, CVE-2021-44228 does not affect Apache Guacamole. Guacamole uses
[Logback](http://logback.qos.ch/) as its logging backend, not Log4j.
Expand Down