Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerability in Artifactory: CVE-2020-11023 #1970

Open
varadajadhav opened this issue Feb 25, 2025 · 4 comments
Open

Security Vulnerability in Artifactory: CVE-2020-11023 #1970

varadajadhav opened this issue Feb 25, 2025 · 4 comments

Comments

@varadajadhav
Copy link

Hello Team,

We have identified a security vulnerability in our Artifactory installation for CVE-2020-11023. During our investigation, the affected vulnerable packages are - libgcc, libstdc++-devel and libstdc++

Our current Artifactory version is 7.98.8. Could you confirm if this is vulnerable in this version? If so, could you provide guidance on how to address this issue?

Please let me know if you need any additional details from my side.

Thank you!

Image

@vijayreddy1991
Copy link

Hi @varadajadhav
The issue has been resolved in the latest release of Artifactory version 7.98.x. Please upgrade to latest version

@varadajadhav
Copy link
Author

Can you please share the link of the doc where it's mentioned which 7.98.x version we need to use

@amithins
Copy link
Collaborator

Apologies, the fix was implemented internally. It was overlooked in the previous message. It will be included in the upcoming patch for version 7.104.

@varadajadhav
Copy link
Author

When do we expect the patch to be released?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants