Skip to content

PD-14292 Omit contributor email from API work reads - #7755

Merged
amontenegro merged 2 commits into
mainfrom
lmendoa/PD-14292-strip-contributor-email-main
Oct 8, 2026
Merged

amontenegro merged 2 commits into
mainfrom
lmendoa/PD-14292-strip-contributor-email-main

Conversation

@cryptalith

@cryptalith cryptalith commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

No description provided.

@orcid-sast

orcid-sast Bot commented Oct 8, 2026

Copy link
Copy Markdown

Semgrep found 3 ssc-fedf6bab-e20c-4f00-86a0-12bdb3497926 findings:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.httpcomponents.core5:httpcore5-h2 are vulnerable to Uncontrolled Resource Consumption. The HTTP/2 stream multiplexer initializes its HPACK decoder with the protocol initial SETTINGS_MAX_HEADER_LIST_SIZE of Integer.MAX_VALUE instead of the locally configured limit, so the configured maximum header list size is not enforced until the peer acknowledges the local SETTINGS frame. A remote peer can send an oversized compressed header block during that pre-acknowledgement window to force unbounded memory allocation and cause a denial of service. Both HTTP/2 clients and servers are affected, and the default configuration is vulnerable because the limit it specifies is ignored during that same window.

Fix: Upgrade this library to at least version 5.4.3 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:129.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41095, GHSA-v3jc-474w-2wm6, CVE-2026-54428

Semgrep found 3 ssc-f7336963-923e-41a8-a6ed-81d763eecbea findings:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. Apache ActiveMQ fails to fully validate non-parenthesized composite discovery wrappers (e.g. masterslave:vm://...,..., static:vm://...) passed to the broker addNetworkConnector(String) and addConnector(String) operations, bypassing the CVE-2026-34197 fix. A crafted discovery URI can spin up a vm:// transport whose brokerConfig loads a remote Spring XML application context via ResourceXmlApplicationContext, resulting in arbitrary code execution in the broker JVM.

Fix: Upgrade this library to at least version 6.2.6 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:150.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33576, GHSA-v853-w46p-fv2h, CVE-2026-34197, CVE-2026-45505

Semgrep found 3 ssc-61dca6de-7d56-4a95-a423-eace2f55b54e findings:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default access policy that permits exec operations on ActiveMQ MBeans. An authenticated attacker can invoke BrokerService.addNetworkConnector(String) with a crafted discovery URI that abuses the VM transport brokerConfig parameter (via a masterslave:// URL) to load an attacker-controlled Spring XML application context, achieving arbitrary code execution through bean factory methods such as Runtime.exec(). Upgrade to 5.19.7 or 6.2.6.

Fix: Upgrade this library to at least version 6.2.6 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:150.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33577, GHSA-hg6c-8mvr-jqc9, CVE-2026-42588

Semgrep found 3 ssc-a9fb67db-b7db-4f1c-b697-50b6fc9bde37 findings:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Control of Generation of Code ('Code Injection') / Improper Input Validation. An authenticated attacker can bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia when the activemq-http module is on the classpath. A malicious HTTP endpoint can return a VM transport through the HTTP URI which bypasses the validation added in CVE-2026-34197. The attacker can then use the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().

Fix: Upgrade this library to at least version 6.2.5 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:150.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25410, GHSA-w3w2-mpp5-92gm, CVE-2026-40466

Semgrep found 3 ssc-4a2173e8-253a-468a-8541-9668c7792389 findings:

🟠 High severity issue identified in your code:

Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. An authenticated attacker can exploit this vulnerability by using the Apache ActiveMQ admin web console to construct a malicious broker name that bypasses name validation to include an xbean binding. The attacker can then use the DestinationView mbean to send a message that triggers a VM transport creation referencing the malicious broker name, causing Spring ResourceXmlApplicationContext to load a remote Spring XML application context. Because Spring instantiates all singleton beans before BrokerService validates the configuration, this leads to arbitrary code execution on the broker JVM through bean factory methods such as Runtime.exec().

Fix: Upgrade this library to at least version 6.2.5 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:150.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25412, GHSA-mr6m-xj7v-3cv3, CVE-2026-41044

Semgrep found 2 ssc-594aaa01-1c1c-493a-861d-e1e354b84905 findings:

  • orcid-api-web/maven_dep_tree.txt
  • orcid-pub-web/maven_dep_tree.txt

🟠 High severity issue identified in your code:

Risk: Affected versions of org.eclipse.jetty.http2:http2-common and org.eclipse.jetty.http2:jetty-http2-common are vulnerable to Allocation of Resources Without Limits or Throttling / Uncontrolled Resource Consumption. A malicious HTTP/2 client can send malformed control frames (for example, WINDOW_UPDATE frames with a zero or overflow increment, HEADERS/DATA on half-closed streams, or mis-framed PRIORITY frames) to Eclipse Jetty's HTTP/2 server, triggering RST_STREAM responses that prematurely decrement the active‐stream counter. This lets an attacker repeatedly open new streams on a single connection without ever hitting the max-concurrent-streams limit, exhausting CPU and/or memory and resulting in denial of service. This is a protocol level attack.

Fix: Upgrade this library to at least version 9.4.58 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:37.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25397, GHSA-mmxm-8w33-wc4h, CVE-2025-5115

Semgrep found 2 ssc-0583e480-5b5d-417c-9943-a424ac4588cd findings:

🟠 High severity issue identified in your code:

Risk: protobuf-java and protobuf-javalite 3.21.x before 3.21.7, 3.20.x before 3.20.3, 3.19.x before 3.19.6, 3.16.x before 3.16.3 are vulnerable to a Denial of Service (DoS) attack through specially crafted input messages. It is recommended to upgrade protobuf-java and protobuf-javalite 3.21.x to 3.21.7, 3.20.x to 3.20.3, 3.19.x to 3.19.6, and 3.16.x to 3.16.3.

Fix: Upgrade this library to at least version 3.19.6 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:224.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7625, GHSA-g5ww-5jh7-63cx, CVE-2022-3509

Semgrep found 2 ssc-0d85f8b9-38de-4837-8381-552321fc4824 findings:

  • orcid-api-web/maven_dep_tree.txt
  • orcid-pub-web/maven_dep_tree.txt

🟠 High severity issue identified in your code:

Risk: Affected versions of org.eclipse.jetty.http3:http3-qpack, org.eclipse.jetty:jetty-http, and org.eclipse.jetty.http2:http2-hpack are vulnerable to Integer Overflow Or Wraparound. An attacker can exploit the integer overflow in MetaDataBuilder.checkSize to manipulate HTTP/2 HPACK header values, potentially causing buffer overflows and server memory exhaustion by sending crafted headers.

Fix: Upgrade this library to at least version 9.4.53 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:38.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2828, GHSA-wgh7-54f2-x98r, CVE-2023-36478

@amontenegro

Copy link
Copy Markdown
Member

@amontenegro
amontenegro merged commit f0e145c into main Oct 8, 2026
21 of 23 checks passed
@amontenegro
amontenegro deleted the lmendoa/PD-14292-strip-contributor-email-main branch October 8, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants