Security (SCA): Critical/High/Medium CVEs detected in redhat.java (Language Support for Java™ by Red Hat) — remediation required
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- java, typescript, vscode
调研方向
从 redhat.java VSIX 和 secure.software 漏洞报告开始,然后追踪每个列出的 CVE,确定其直接或传递依赖项以及受影响的版本。更新受影响的依赖项,重新构建扩展 artifact 并重新扫描;当 Critical、High 和 Medium 发现项全部清除后,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Summary
ReversingLabs (secure.software) reports multiple fixable vulnerabilities in the recent VS Code extension package Language Support for Java™ by Red Hat (redhat.java) releases. The vulnerability list includes 1 Critical, 1 High, and 3 Medium severity CVEs (per CVSS), each marked with Fix Available (and one marked Exploits Exist). [secure.software]
Source report: secure.software — redhat/java vulnerabilities
Last refreshed (per report): 2026-03-14 [secure.software]
Findings (Critical / High / Medium only)
The secure.software report lists the following CVEs:
Critical
- CVE-2017-1000487 — CVSS 9.8 (Critical) — Fix Available — “Vulnerability Triaged” [secure.software]
High
- CVE-2022-4244 — CVSS 7.5 (High) — Fix Available — “Vulnerability Triaged” [secure.software]
Medium
- CVE-2022-36033 — CVSS 6.1 (Medium) — Exploits Exist, Fix Available [secure.software]
- CVE-2022-4245 — CVSS 4.3 (Medium) — Fix Available — “Vulnerability Triaged” [secure.software]
- CVE-2024-47554 — CVSS 4.3 (Medium) — Fix Available [secure.software]
The report indicates: “All detected vulnerabilities are fixable” and recommends running update/upgrade actions to resolve them. [secure.software]
Why This Matters
Although these vulnerabilities originate in third‑party libraries, if left unpatched they may introduce avoidable security risks to developer environments and create barriers to RedHat VSCode Java extension adoption within enterprise environments.
Recommended remediation approach
- Dependency trace / SBOM: Identify which direct/transitive libraries in the VSIX map to each CVE and confirm the impacted versions.
- Upgrade / patch: Update affected dependencies to versions that address: CVE‑2017‑1000487; CVE‑2022‑4244; CVE‑2022‑36033; CVE‑2022‑4245; CVE‑2024‑47554 [secure.software]
- Rebuild & validate: Rebuild the extension artifact and re-scan to confirm Critical/High/Medium findings are cleared.
References: ReversingLabs secure.software report: Language Support for Java™ by Red Hat — Vulnerabilities
- 主要语言
- TypeScript
- 星标
- 2.3k
- 派生
- 547
- 平均合并
- 20 小时 9 分钟
- 30 天内合并 PR
- 10
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
redhat-developer/vscode-java 的其他 Issue
-
bug
难度 1/5 1 小时以内 新手友好度 85/100
redhat-developer/vscode-java#4509 ·
-
难度 2/5 1-3 小时 新手友好度 68/100
redhat-developer/vscode-java#4426 ·
-
bug
难度 4/5 3-5 天 新手友好度 45/100
redhat-developer/vscode-java#4506 · 3 条评论 · 4 个 reaction ·
-
bug
难度 4/5 3-5 天 新手友好度 45/100
redhat-developer/vscode-java#4505 · 2 条评论 · 2 个 reaction ·
-
难度 4/5 3-5 天 新手友好度 52/100
redhat-developer/vscode-java#4504 · 3 条评论 · 1 个 reaction ·
查看 redhat-developer/vscode-java 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 65/100
-
难度 2/5 1-3 小时 新手友好度 75/100
-
bug v2
难度 2/5 1-3 小时 新手友好度 75/100
modelcontextprotocol/inspector#2458 · 1 条评论 ·
-
难度 1/5 1 小时以内 新手友好度 75/100
railmapgen/rmp-gallery#4068 ·
-
Mend: dependency security vulnerability status: needs triage 🕵️♀️
难度 2/5 1-3 小时 新手友好度 70/100
carbon-design-system/ibm-products#9907 ·