Skip to main content

Changes in Update Released on 03-January-2024

This update includes the changes described in the following sections.

Issues/Bugs Addressed

The following issues were addressed in the Update:

Updates to Apache Struts Components

Added vulnerability information to the following apache-struts components:

Component IDNameURL
33042apache-strutshttp://struts\.apache\.org​
565248struts2-corehttps://repo1\.maven\.org/maven2/org/apache/struts/struts2\-core​
738786apache-strutshttps://github\.com/apache/struts​
5398957strutshttp://struts\.apache\.org/​

Issues Addressed

The following issues were addressed in the Update:

Issue IDIssue Summary
SCA-51793Addition of vulnerability mappings for Apache struts component for CVE-2023-50164 (https://nvd\.nist\.gov/vuln/detail/CVE\-2023\-50164​\)\. Updated component/version info for the below components
SCA-51532Addition of new licenses to data library MICROSOFT.WEB.XDT and MICROSOFT ASP.NET SIGNALR and also updating component/version information for Nuget components
SCA-51265, SCA-51033Updating component/version information for Npmjs/Pypi components.

Collector Status

The following table lists Collector Status information.

NameDate of Last Successful Run
npm12/28/2023
crates8/25/2022
cpan12/28/2023
clojars12/28/2023
rubygems12/21/2023
maven-google12/22/2023
cran12/23/2023
hackage12/24/2023
packagist12/24/2023
go12/27/2023
pypi12/27/2023
nuget gallery12/21/2023
maven2-ibiblio12/06/2023
github12/27/2023
fedora-koji12/13/2023
alpine12/27/2023
gitlab6/6/2023
debian12/25/2023