Security (SCA): Critical/High/Medium CVEs detected in redhat.java (Language Support for Java™ by Red Hat) — remediation required
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- java, typescript, vscode
Hướng nghiên cứu
Bắt đầu với redhat.java VSIX và báo cáo lỗ hổng của secure.software, sau đó truy vết từng CVE được liệt kê đến dependency trực tiếp hoặc bắc cầu của nó và phiên bản bị ảnh hưởng. Cập nhật các dependency bị ảnh hưởng, build lại artifact của extension và quét lại; được xem là hoàn tất khi các phát hiện Critical, High và Medium được loại bỏ.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
ReversingLabs (secure.software) reports multiple fixable vulnerabilities in the recent VS Code extension package Language Support for Java™ by Red Hat (redhat.java) releases. The vulnerability list includes 1 Critical, 1 High, and 3 Medium severity CVEs (per CVSS), each marked with Fix Available (and one marked Exploits Exist). [secure.software]
Source report: secure.software — redhat/java vulnerabilities
Last refreshed (per report): 2026-03-14 [secure.software]
Findings (Critical / High / Medium only)
The secure.software report lists the following CVEs:
Critical
- CVE-2017-1000487 — CVSS 9.8 (Critical) — Fix Available — “Vulnerability Triaged” [secure.software]
High
- CVE-2022-4244 — CVSS 7.5 (High) — Fix Available — “Vulnerability Triaged” [secure.software]
Medium
- CVE-2022-36033 — CVSS 6.1 (Medium) — Exploits Exist, Fix Available [secure.software]
- CVE-2022-4245 — CVSS 4.3 (Medium) — Fix Available — “Vulnerability Triaged” [secure.software]
- CVE-2024-47554 — CVSS 4.3 (Medium) — Fix Available [secure.software]
The report indicates: “All detected vulnerabilities are fixable” and recommends running update/upgrade actions to resolve them. [secure.software]
Why This Matters
Although these vulnerabilities originate in third‑party libraries, if left unpatched they may introduce avoidable security risks to developer environments and create barriers to RedHat VSCode Java extension adoption within enterprise environments.
Recommended remediation approach
- Dependency trace / SBOM: Identify which direct/transitive libraries in the VSIX map to each CVE and confirm the impacted versions.
- Upgrade / patch: Update affected dependencies to versions that address: CVE‑2017‑1000487; CVE‑2022‑4244; CVE‑2022‑36033; CVE‑2022‑4245; CVE‑2024‑47554 [secure.software]
- Rebuild & validate: Rebuild the extension artifact and re-scan to confirm Critical/High/Medium findings are cleared.
References: ReversingLabs secure.software report: Language Support for Java™ by Red Hat — Vulnerabilities
- Ngôn ngữ chính
- TypeScript
- Star
- 2.3k
- Fork
- 547
- Merge trung bình
- 20 giờ 9 phút
- Pull request đã merge (30 ngày)
- 10
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của redhat-developer/vscode-java
-
bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
redhat-developer/vscode-java#4509 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
redhat-developer/vscode-java#4426 ·
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
redhat-developer/vscode-java#4506 · 3 bình luận · 4 reaction ·
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
redhat-developer/vscode-java#4505 · 2 bình luận · 2 reaction ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
redhat-developer/vscode-java#4504 · 3 bình luận · 1 reaction ·
Tất cả issue của redhat-developer/vscode-java
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
bug v2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
modelcontextprotocol/inspector#2458 · 1 bình luận ·
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 75/100
railmapgen/rmp-gallery#4068 ·
-
Mend: dependency security vulnerability status: needs triage 🕵️♀️
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
carbon-design-system/ibm-products#9907 ·