OPENSUSE-SU-2026:22009-1
Vulnerability from csaf_opensuse - Published: 2026-10-01 12:14 - Updated: 2026-10-03 16:17Summary
Security update for jline3
Severity
Moderate
Notes
Title of the patch: Security update for jline3
Description of the patch: This update for jline3 fixes the following issue:
Update to upstream version 3.30.17:
* Security Fixes
+ Native Stack Buffer Overflow in Public INPUT_RECORD.memmove
JNI Method (Windows) (GHSA-6r3w-6jpj-x5w6)
+ Authenticated SSH Shell Channel Resource Leak via Null or
Non-Numeric PTY Dimensions (GHSA-7h86-pjwh-gpqj)
+ Authenticated SSH DoS via Unbounded Window-Change Terminal
Geometry (GHSA-m935-wqpj-pvp3)
+ TCP Socket File Descriptor Leak When Maximum Connections
Reached (GHSA-c87g-867h-cqr6)
* Bug Fixes
+ strip control characters from file names in posix builtins
+ bound !# history expansion to prevent exponential blowup
+ verify server host keys in the ssh client builtin
+ address remaining security vulnerabilities reported by
AFINE/CERT.PL
+ backport security fixes from master
+ backport security fixes to 3.x (path traversal + DSR plain
text)
+ strip control characters from ssh banner and prompts
* Dependency updates
+ bump com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to
3.10.2
+ bump slf4j.version from 2.0.18 to 2.0.19
+ bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6
to 3.6.0
+ bump org.apache.maven.plugins:maven-compiler-plugin from
3.15.0 to 3.16.0
+ bump org.apache.felix:maven-bundle-plugin from 6.0.2 to 6.1.2
+ bump actions/setup-java from 5 to 6.0.0
+ bump org.graalvm.sdk:graal-sdk from 25.1.3 to 25.3.4.1
+ bump com.mycila:license-maven-plugin from 5.0.0 to 5.1.2
+ bump org.easymock:easymock from 5.6.0 to 5.7.0
+ bump com.google.jimfs:jimfs from 1.3.1 to 1.3.2
+ bump org.apache.maven.wrapper:maven-wrapper from 3.3.2 to
3.3.4
+ bump org.apache.maven:apache-maven from 4.0.0-rc-3 to
4.0.0-rc-6
+ bump eu.maveniverse.maven.njord:extension3 from 0.9.9 to
0.9.10
+ bump com.palantir.javaformat:palantir-java-format from 2.96.0
to 2.97.0
+ bump release-drafter/release-drafter from 7.6.0 to 7.7.0
+ bump groovy.version from 4.0.32 to 4.0.33
+ bump release-drafter/release-drafter from 7 to 7.6.0
+ bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to
3.5.1
- Update to upstream version 3.30.16
* bugfix release with security hardening, SSH agent forwarding
fix, and terminal compatibility improvements.
* Breaking Changes
+ SSH agent forwarding is no longer enabled by default;
pass -A to explicitly request it
+ reject overlong hex components in OSC color responses
+ strip OSC and other escape sequences in ansiAppend
+ search multiple lib paths for versioned libutil.so
+ use Path.resolve instead of URI.resolve in cat and sort to
prevent SSRF
+ check closed flag in PtyInputStream to prevent hang on empty
input
+ confine ConfigurationPath lookups to the config directory
+ disable Read File command in nano restricted mode
+ drain buffered data before EOF in NonBlockingPumpInputStream
+ look up openpty in libc.so.6 for glibc 2.34+
+ guard styleMatches and highlighter rules against ReDoS
+ backport telnet DoS mitigations (GHSA-47qp, GHSA-2r2c)
+ propagate EOF in PtyInputStream to avoid infinite loop
+ bump org.apache.ivy:ivy from 2.5.3 to 2.6.0
+ bump actions/setup-node from 6 to 7
+ bump com.palantir.javaformat:palantir-java-format from 2.94.0
to 2.96.0
+ bump sshd.version from 2.18.0 to 2.19.0
+ bump org.codehaus.gmavenplus:gmavenplus-plugin from 5.0.0 to
5.1.0
+ bump org.graalvm.sdk:graal-sdk from 25.0.3 to 25.1.3
+ bump com.diffplug.spotless:spotless-maven-plugin
Patchnames: openSUSE-Leap-16.0-1800
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
References
2 references
| URL | Category |
|---|---|
| https://www.suse.com/support/security/rating/ | external |
| https://ftp.suse.com/pub/projects/security/csaf/o… | self |
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "moderate"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "Security update for jline3",
"title": "Title of the patch"
},
{
"category": "description",
"text": "This update for jline3 fixes the following issue:\n\nUpdate to upstream version 3.30.17:\n\n * Security Fixes\n + Native Stack Buffer Overflow in Public INPUT_RECORD.memmove\n JNI Method (Windows) (GHSA-6r3w-6jpj-x5w6)\n + Authenticated SSH Shell Channel Resource Leak via Null or\n Non-Numeric PTY Dimensions (GHSA-7h86-pjwh-gpqj)\n + Authenticated SSH DoS via Unbounded Window-Change Terminal\n Geometry (GHSA-m935-wqpj-pvp3)\n + TCP Socket File Descriptor Leak When Maximum Connections\n Reached (GHSA-c87g-867h-cqr6)\n * Bug Fixes\n + strip control characters from file names in posix builtins\n + bound !# history expansion to prevent exponential blowup\n + verify server host keys in the ssh client builtin\n + address remaining security vulnerabilities reported by\n AFINE/CERT.PL\n + backport security fixes from master\n + backport security fixes to 3.x (path traversal + DSR plain\n text)\n + strip control characters from ssh banner and prompts\n * Dependency updates\n + bump com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to\n 3.10.2\n + bump slf4j.version from 2.0.18 to 2.0.19\n + bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6\n to 3.6.0\n + bump org.apache.maven.plugins:maven-compiler-plugin from\n 3.15.0 to 3.16.0\n + bump org.apache.felix:maven-bundle-plugin from 6.0.2 to 6.1.2\n + bump actions/setup-java from 5 to 6.0.0\n + bump org.graalvm.sdk:graal-sdk from 25.1.3 to 25.3.4.1\n + bump com.mycila:license-maven-plugin from 5.0.0 to 5.1.2\n + bump org.easymock:easymock from 5.6.0 to 5.7.0\n + bump com.google.jimfs:jimfs from 1.3.1 to 1.3.2\n + bump org.apache.maven.wrapper:maven-wrapper from 3.3.2 to\n 3.3.4\n + bump org.apache.maven:apache-maven from 4.0.0-rc-3 to\n 4.0.0-rc-6\n + bump eu.maveniverse.maven.njord:extension3 from 0.9.9 to\n 0.9.10\n + bump com.palantir.javaformat:palantir-java-format from 2.96.0\n to 2.97.0\n + bump release-drafter/release-drafter from 7.6.0 to 7.7.0\n + bump groovy.version from 4.0.32 to 4.0.33\n + bump release-drafter/release-drafter from 7 to 7.6.0\n + bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to\n 3.5.1\n- Update to upstream version 3.30.16\n * bugfix release with security hardening, SSH agent forwarding\n fix, and terminal compatibility improvements.\n * Breaking Changes\n + SSH agent forwarding is no longer enabled by default;\n pass -A to explicitly request it\n + reject overlong hex components in OSC color responses\n + strip OSC and other escape sequences in ansiAppend\n + search multiple lib paths for versioned libutil.so\n + use Path.resolve instead of URI.resolve in cat and sort to\n prevent SSRF\n + check closed flag in PtyInputStream to prevent hang on empty\n input\n + confine ConfigurationPath lookups to the config directory\n + disable Read File command in nano restricted mode\n + drain buffered data before EOF in NonBlockingPumpInputStream\n + look up openpty in libc.so.6 for glibc 2.34+\n + guard styleMatches and highlighter rules against ReDoS\n + backport telnet DoS mitigations (GHSA-47qp, GHSA-2r2c)\n + propagate EOF in PtyInputStream to avoid infinite loop\n + bump org.apache.ivy:ivy from 2.5.3 to 2.6.0\n + bump actions/setup-node from 6 to 7\n + bump com.palantir.javaformat:palantir-java-format from 2.94.0\n to 2.96.0\n + bump sshd.version from 2.18.0 to 2.19.0\n + bump org.codehaus.gmavenplus:gmavenplus-plugin from 5.0.0 to\n 5.1.0\n + bump org.graalvm.sdk:graal-sdk from 25.0.3 to 25.1.3\n + bump com.diffplug.spotless:spotless-maven-plugin\n",
"title": "Description of the patch"
},
{
"category": "details",
"text": "openSUSE-Leap-16.0-1800",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_22009-1.json"
}
],
"title": "Security update for jline3",
"tracking": {
"current_release_date": "2026-10-03T16:17:00Z",
"generator": {
"date": "2026-10-01T12:14:32Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "openSUSE-SU-2026:22009-1",
"initial_release_date": "2026-10-01T12:14:32Z",
"revision_history": [
{
"date": "2026-10-01T12:14:32Z",
"number": "1",
"summary": "Current version"
},
{
"date": "2026-10-03T16:17:00Z",
"number": "2",
"summary": "unknown changes"
}
],
"status": "final",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "jline3-0:3.30.17-160000.1.1.aarch64",
"product": {
"name": "jline3-0:3.30.17-160000.1.1.aarch64",
"product_id": "jline3-0:3.30.17-160000.1.1.aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3@3.30.17-160000.1.1?arch=aarch64\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-jansi-0:3.30.17-160000.1.1.aarch64",
"product": {
"name": "jline3-jansi-0:3.30.17-160000.1.1.aarch64",
"product_id": "jline3-jansi-0:3.30.17-160000.1.1.aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-jansi@3.30.17-160000.1.1?arch=aarch64\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-native-0:3.30.17-160000.1.1.aarch64",
"product": {
"name": "jline3-native-0:3.30.17-160000.1.1.aarch64",
"product_id": "jline3-native-0:3.30.17-160000.1.1.aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-native@3.30.17-160000.1.1?arch=aarch64\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
}
],
"category": "architecture",
"name": "aarch64"
},
{
"branches": [
{
"category": "product_version",
"name": "jline3-builtins-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-builtins-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-builtins-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-builtins@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-console-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-console-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-console-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-console@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-console-ui-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-console-ui-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-console-ui-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-console-ui@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-curses-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-curses-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-curses-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-curses@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-jansi-core-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-jansi-core-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-jansi-core-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-jansi-core@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-javadoc-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-javadoc-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-javadoc-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-javadoc@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-reader-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-reader-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-reader-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-reader@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-remote-telnet-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-remote-telnet-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-remote-telnet-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-remote-telnet@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-style-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-style-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-style-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-style@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-terminal-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-terminal-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-terminal-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-terminal@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-terminal-jansi-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-terminal-jansi-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-terminal-jansi-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-terminal-jansi@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-terminal-jna-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-terminal-jna-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-terminal-jna-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-terminal-jna@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-terminal-jni-0:3.30.17-160000.1.1.noarch",
"product": {
"name": "jline3-terminal-jni-0:3.30.17-160000.1.1.noarch",
"product_id": "jline3-terminal-jni-0:3.30.17-160000.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-terminal-jni@3.30.17-160000.1.1?arch=noarch\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
}
],
"category": "architecture",
"name": "noarch"
},
{
"branches": [
{
"category": "product_version",
"name": "jline3-0:3.30.17-160000.1.1.ppc64le",
"product": {
"name": "jline3-0:3.30.17-160000.1.1.ppc64le",
"product_id": "jline3-0:3.30.17-160000.1.1.ppc64le",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3@3.30.17-160000.1.1?arch=ppc64le\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-jansi-0:3.30.17-160000.1.1.ppc64le",
"product": {
"name": "jline3-jansi-0:3.30.17-160000.1.1.ppc64le",
"product_id": "jline3-jansi-0:3.30.17-160000.1.1.ppc64le",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-jansi@3.30.17-160000.1.1?arch=ppc64le\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-native-0:3.30.17-160000.1.1.ppc64le",
"product": {
"name": "jline3-native-0:3.30.17-160000.1.1.ppc64le",
"product_id": "jline3-native-0:3.30.17-160000.1.1.ppc64le",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-native@3.30.17-160000.1.1?arch=ppc64le\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
}
],
"category": "architecture",
"name": "ppc64le"
},
{
"branches": [
{
"category": "product_version",
"name": "jline3-0:3.30.17-160000.1.1.s390x",
"product": {
"name": "jline3-0:3.30.17-160000.1.1.s390x",
"product_id": "jline3-0:3.30.17-160000.1.1.s390x",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3@3.30.17-160000.1.1?arch=s390x\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-jansi-0:3.30.17-160000.1.1.s390x",
"product": {
"name": "jline3-jansi-0:3.30.17-160000.1.1.s390x",
"product_id": "jline3-jansi-0:3.30.17-160000.1.1.s390x",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-jansi@3.30.17-160000.1.1?arch=s390x\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-native-0:3.30.17-160000.1.1.s390x",
"product": {
"name": "jline3-native-0:3.30.17-160000.1.1.s390x",
"product_id": "jline3-native-0:3.30.17-160000.1.1.s390x",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-native@3.30.17-160000.1.1?arch=s390x\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
}
],
"category": "architecture",
"name": "s390x"
},
{
"branches": [
{
"category": "product_version",
"name": "jline3-0:3.30.17-160000.1.1.x86_64",
"product": {
"name": "jline3-0:3.30.17-160000.1.1.x86_64",
"product_id": "jline3-0:3.30.17-160000.1.1.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3@3.30.17-160000.1.1?arch=x86_64\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-jansi-0:3.30.17-160000.1.1.x86_64",
"product": {
"name": "jline3-jansi-0:3.30.17-160000.1.1.x86_64",
"product_id": "jline3-jansi-0:3.30.17-160000.1.1.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-jansi@3.30.17-160000.1.1?arch=x86_64\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
},
{
"category": "product_version",
"name": "jline3-native-0:3.30.17-160000.1.1.x86_64",
"product": {
"name": "jline3-native-0:3.30.17-160000.1.1.x86_64",
"product_id": "jline3-native-0:3.30.17-160000.1.1.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/jline3-native@3.30.17-160000.1.1?arch=x86_64\u0026upstream=jline3-0:3.30.17-160000.1.1.src.rpm"
}
}
}
],
"category": "architecture",
"name": "x86_64"
},
{
"branches": [
{
"category": "product_name",
"name": "openSUSE Leap 16.0",
"product": {
"name": "openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0"
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-0:3.30.17-160000.1.1.aarch64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-0:3.30.17-160000.1.1.aarch64"
},
"product_reference": "jline3-0:3.30.17-160000.1.1.aarch64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-0:3.30.17-160000.1.1.ppc64le as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-0:3.30.17-160000.1.1.ppc64le"
},
"product_reference": "jline3-0:3.30.17-160000.1.1.ppc64le",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-0:3.30.17-160000.1.1.s390x as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-0:3.30.17-160000.1.1.s390x"
},
"product_reference": "jline3-0:3.30.17-160000.1.1.s390x",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-0:3.30.17-160000.1.1.x86_64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-0:3.30.17-160000.1.1.x86_64"
},
"product_reference": "jline3-0:3.30.17-160000.1.1.x86_64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-builtins-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-builtins-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-builtins-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-console-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-console-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-console-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-console-ui-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-console-ui-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-console-ui-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-curses-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-curses-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-curses-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-jansi-0:3.30.17-160000.1.1.aarch64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-jansi-0:3.30.17-160000.1.1.aarch64"
},
"product_reference": "jline3-jansi-0:3.30.17-160000.1.1.aarch64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-jansi-0:3.30.17-160000.1.1.ppc64le as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-jansi-0:3.30.17-160000.1.1.ppc64le"
},
"product_reference": "jline3-jansi-0:3.30.17-160000.1.1.ppc64le",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-jansi-0:3.30.17-160000.1.1.s390x as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-jansi-0:3.30.17-160000.1.1.s390x"
},
"product_reference": "jline3-jansi-0:3.30.17-160000.1.1.s390x",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-jansi-0:3.30.17-160000.1.1.x86_64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-jansi-0:3.30.17-160000.1.1.x86_64"
},
"product_reference": "jline3-jansi-0:3.30.17-160000.1.1.x86_64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-jansi-core-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-jansi-core-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-jansi-core-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-javadoc-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-javadoc-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-javadoc-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-native-0:3.30.17-160000.1.1.aarch64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-native-0:3.30.17-160000.1.1.aarch64"
},
"product_reference": "jline3-native-0:3.30.17-160000.1.1.aarch64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-native-0:3.30.17-160000.1.1.ppc64le as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-native-0:3.30.17-160000.1.1.ppc64le"
},
"product_reference": "jline3-native-0:3.30.17-160000.1.1.ppc64le",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-native-0:3.30.17-160000.1.1.s390x as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-native-0:3.30.17-160000.1.1.s390x"
},
"product_reference": "jline3-native-0:3.30.17-160000.1.1.s390x",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-native-0:3.30.17-160000.1.1.x86_64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-native-0:3.30.17-160000.1.1.x86_64"
},
"product_reference": "jline3-native-0:3.30.17-160000.1.1.x86_64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-reader-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-reader-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-reader-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-remote-telnet-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-remote-telnet-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-remote-telnet-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-style-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-style-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-style-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-terminal-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-terminal-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-terminal-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-terminal-jansi-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-terminal-jansi-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-terminal-jansi-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-terminal-jna-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-terminal-jna-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-terminal-jna-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "jline3-terminal-jni-0:3.30.17-160000.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:jline3-terminal-jni-0:3.30.17-160000.1.1.noarch"
},
"product_reference": "jline3-terminal-jni-0:3.30.17-160000.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
}
]
}
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…