Skip to content
Snippets Groups Projects
Kairo de Araujo's avatar
closed issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement
Kairo de Araujo's avatar
commented on issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement

CVE CVE-2025-4949 is published.

Kairo de Araujo's avatar
commented on issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement

Ok, I'll use the suggestion above

Matthias Sohn's avatar
commented on issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement

I don't know how to translate CVSS 3.1 to 4

Kairo de Araujo's avatar
commented on issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement

Here is the CVSS4 suggestion: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green

Kairo de Araujo's avatar
commented on issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement

In order to published the CVE, can you please translate the CVSS3.1 to CVSS4...

Matthias Sohn's avatar
commented on issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement

yes, please

Mikaël Barbero's avatar
commented on issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement

We will use CVE-2025-4949 for this one. It's currently only reserved. As the fix has been already published, should we publish the CVE as well?

Matthias Sohn's avatar
opened issue #64 "CVE for https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281" at Eclipse Projects Security / cve-assignement
Tiago Lucas's avatar
closed issue #61 "technology.openj9 Fix call to propsfile_read_text buffer length calculation" at Eclipse Projects Security / cve-assignement
Peter Shipton's avatar
commented on issue #61 "technology.openj9 Fix call to propsfile_read_text buffer length calculation" at Eclipse Projects Security / cve-assignement

Thanks, this can be made non confidential and closed.

Tiago Lucas's avatar
commented on issue #61 "technology.openj9 Fix call to propsfile_read_text buffer length calculation" at Eclipse Projects Security / cve-assignement

The CVE entry was created: https://www.cve.org/cverecord?id=CVE-2025-4447 @pshipton Anything else we can do on this topic?

Peter Shipton's avatar
commented on issue #61 "technology.openj9 Fix call to propsfile_read_text buffer length calculation" at Eclipse Projects Security / cve-assignement

@tiagolucas any update?

Tiago Lucas's avatar
commented on issue #61 "technology.openj9 Fix call to propsfile_read_text buffer length calculation" at Eclipse Projects Security / cve-assignement

Yes it will.

Peter Shipton's avatar
commented on issue #61 "technology.openj9 Fix call to propsfile_read_text buffer length calculation" at Eclipse Projects Security / cve-assignement

@tiagolucas will it be published today?

Peter Shipton's avatar
commented on issue #61 "technology.openj9 Fix call to propsfile_read_text buffer length calculation" at Eclipse Projects Security / cve-assignement

Sorry, yes, it's ready to be published.