You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Our security code and 3d party product review team reported that one of core BIRT ReportEngine runtime jars, e.g.:
org.eclipse.birt.runtime_4.10.0-20220721.jar or previous build version org.eclipse.birt.runtime_4.9.0-20220315.jar both use Apache Cassandra library - org.apache.cassandra:cassandra-thrift:1.1.0.
The BIRT ReportEngine Runtime is not a web application. It is a local report renderer and, therefore, not subject to the effects described in your CVE.
Our security code and 3d party product review team reported that one of core BIRT ReportEngine runtime jars, e.g.:
org.eclipse.birt.runtime_4.10.0-20220721.jar or previous build version org.eclipse.birt.runtime_4.9.0-20220315.jar both use Apache Cassandra library - org.apache.cassandra:cassandra-thrift:1.1.0.
This library has critical (score 9.1) security vulnerability reported by NIST. For more details, please, see here: https://nvd.nist.gov/vuln/detail/CVE-2021-44521.
Thanks,
Aleksey
Deltek
The text was updated successfully, but these errors were encountered: