Menu

Version of hazelcast-all used by jamon has security vulnerability

2019-10-25
2024-05-04
  • Chuck Dumont

    Chuck Dumont - 2019-10-25

    The security scans for our product have identified a vulnerability in hazelcast-all, which is a dependency of jamon. See https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10750

    Could you please either update hazelcast-all to version 3.11 or later and publish a new release, or else post a statement to this forum indicating that jamon is not affected by this vulnerability? Thanks.

     
  • Steve Souza

    Steve Souza - 2024-05-04

    Sorry, for the ridiculously late/pointless response, but thought I would answer in case others look.

    1. I hope to update all the libraries jamon uses including hazelcast relatively soon.
    2. If you don't have hazelcast jars in your classpath it won't call any of the hazelcast code. You can also explicitly configure the jamonpersister in the jamon properties file to ensure hazelcast code is not called.
    3. If you would like you can safely remove all hazelcast classes from the jar. I could work with you on this.
     

Log in to post a comment.

MongoDB Logo MongoDB