Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2014-3518 is not detected #28

Open
silvag opened this issue Aug 2, 2014 · 3 comments
Open

CVE-2014-3518 is not detected #28

silvag opened this issue Aug 2, 2014 · 3 comments
Assignees

Comments

@silvag
Copy link

silvag commented Aug 2, 2014

I executed the victims jar against jboss-jmx-remoting.jar expecting to detect CVE-2014-3518. However, nothing was shown. My local DB is being updated at the time of execution but not sure the right information is available to detect this vulnerability.

@abn
Copy link
Member

abn commented Aug 3, 2014

@silvag at the moment the entry for CVE-2014-3518 is only available within https://github.com/victims/victims-cve-db automation for adding entries for the EVD is not yet present and this entry has not yet been manually added to the EVD fingerprint database. This is why the client cannot detect the vulnerable artifact.

@silvag
Copy link
Author

silvag commented Aug 3, 2014

Hi Arun Babu,
Thanks for the quick response. That explains it. I thought I might be missing something when I found it in the cve-db.
Could I manually add it to the fingerprint database?
Thanks,
Gonzalo Silva Cruz

Arun Babu Neelicattu [email protected] wrote:

@silvag at the moment the entry for CVE-2014-3518 is only available within https://github.com/victims/victims-cve-db automation for adding entries for the EVD is not yet present and this entry has not yet been added to the EVD fingerprint database. This is why the client cannot detect the vulnerable artifact.


Reply to this email directly or view it on GitHub.

@abn abn self-assigned this Aug 3, 2014
@abn
Copy link
Member

abn commented Aug 3, 2014

@silvag contributions are always welcome. You can do that via https://victi.ms/submit/java/ (you'll need to be logged in). We will try get related fingerprints added soon.

I am leaving this bug open till the entry is added. No action required for the client.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants