Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add security page entry for AngularJS vulnerabilities. #147

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions security.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,15 @@ latest would give you an updated image.
No, CVE-2021-44228 does not affect Apache Guacamole. Guacamole uses
[Logback](http://logback.qos.ch/) as its logging backend, not Log4j.

### Is Apache Guacamole affected by AngularJS vulnerabilities? {#not-affected-angularjs}

No. Apache Guacamole does currently rely on AngularJS, which has gone
end-of-life and is no longer being actively developed or supported. While
AngularJS has several vulnerabilities, we have verified that Guacamole
is not impacted by any current known vulnerabilities, either because
the affected component is not in use in Guacamole, or because there is
no known exploitation path.

{% assign releases = site.releases | where: 'released', 'true' | sort: 'date' %}
{% for release in releases reversed %}

Expand Down
Loading