Skip to content
This repository has been archived by the owner on Feb 2, 2023. It is now read-only.

Apple latest Xcode 13.2 #96

Open
MrTechGadget opened this issue Dec 15, 2021 · 4 comments
Open

Apple latest Xcode 13.2 #96

MrTechGadget opened this issue Dec 15, 2021 · 4 comments
Assignees
Labels
need info This issue or pull request requires further information

Comments

@MrTechGadget
Copy link

Submission Template

Please provide the following information.

  • Vendor Name - Apple

  • Product Name - Xcode

  • Version(s) affected - at least the latest, 13.2

  • Status: Unknown.

  • Update Available: No

  • Notes: Xcode.app contains vulnerable Log4j versions embedded
    /Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServices.framework/Versions/A/itms/share/OSGi-Bundles/org.apache.logging.log4j.core-2.11.2.jar
    /System/Volumes/Data/Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServices.framework/Versions/A/itms/share/OSGi-Bundles/org.apache.logging.log4j.core-2.11.2.jar

  • References
    [2021-12-15 16:34:42.246016] VULNERABLE: /System/Volumes/Data/Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServices.framework/Versions/A/itms/share/OSGi-Bundles/org.apache.logging.log4j.core-2.11.2.jar -> org/apache/logging/log4j/core/net/JndiManager.class [04fdd701809d17465c17c7e603b1b202: log4j 2.9.0 - 2.11.2] [2021-12-15 16:35:53.674575] VULNERABLE: /Applications/Xcode.app/Contents/SharedFrameworks/ContentDeliveryServices.framework/Versions/A/itms/share/OSGi-Bundles/org.apache.logging.log4j.core-2.11.2.jar -> org/apache/logging/log4j/core/net/JndiManager.class [04fdd701809d17465c17c7e603b1b202: log4j 2.9.0 - 2.11.2] [2021-12-15 16:36:05.671575] Finished scan, elapsed time: 225.25 seconds

  • Last Updated: 12/15/2021 12:00 EST

@iainDe iainDe self-assigned this Dec 15, 2021
@iainDe
Copy link
Collaborator

iainDe commented Dec 17, 2021

Please provide a public statement or advisory directly addressing the issue with the software named. Thank you

@MrTechGadget
Copy link
Author

MrTechGadget commented Dec 17, 2021 via email

@iainDe
Copy link
Collaborator

iainDe commented Dec 17, 2021

Thank you for the update. We will be looking for the announcement when a public statement is made

@MrTechGadget
Copy link
Author

MrTechGadget commented Dec 17, 2021 via email

@iainDe iainDe added the need info This issue or pull request requires further information label Dec 23, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
need info This issue or pull request requires further information
Projects
None yet
Development

No branches or pull requests

2 participants