Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security flaws scanned by Veracode, including very high flaws #72

Open
VicZhang1 opened this issue Sep 24, 2019 · 10 comments
Open

Security flaws scanned by Veracode, including very high flaws #72

VicZhang1 opened this issue Sep 24, 2019 · 10 comments

Comments

@VicZhang1
Copy link

Hi @MarkusBernhardt ,

We scanned proxy-vole on Veracode, and found some very high flaws as following:
image

image

Seems it's caused by rhino 1.7.7 and JNA 4.2.2. Would you like to take a look at them? or confirm with rhino or Veracode?

@VicZhang1
Copy link
Author

There are new version of JNA https:/java-native-access/jna/releases, are you interesting in upgrading to its new version?

@VicZhang1
Copy link
Author

There are also new version of rhino https://developer.mozilla.org/en-US/docs/Mozilla/Projects/Rhino/Download_Rhino.

@gschnepp
Copy link

gschnepp commented Sep 24, 2019 via email

@VicZhang1
Copy link
Author

VicZhang1 commented Sep 25, 2019

Thanks for your reply @gschnepp . Yeah, we may need to find another choice if this is no longer maintained.

@gschnepp
Copy link

gschnepp commented Sep 25, 2019 via email

@gschnepp
Copy link

Markus doesn't answer any issues or pull requests here for nearly a year now. This project is dead, I think. Unfortunately. :-(

@cpesch
Copy link

cpesch commented May 24, 2020

@gschnepp I'm using proxy-vole in my RouteConverter application and stumbled across some NullPointerException problems. And read your comments below the issues.

Are you aware of an accepted fork of proxy-vole? Or even willing to fork and maintain it?

@gschnepp
Copy link

@cpesch No, unfortunately neither. Well, I'd like to be aware of a fork, but I don't know any. And I don't have enough knowledge of proxies in general to do it.

@cpesch
Copy link

cpesch commented Jun 6, 2020

https:/akuhtz/proxy-vole/commits/master seems to be a promising fork. I've integrated some commits from other forks into it.

Release is published here:
https://repo1.maven.org/maven2/org/bidib/com/github/markusbernhardt/proxy-vole/1.0.6-RC2/

@gschnepp
Copy link

gschnepp commented Jun 7, 2020

Sounds promising! At least it's more living than this here. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants