<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Python Agent 4.5.5 contains vulnerability in Splunk AppDynamics</title>
    <link>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727309#M5704</link>
    <description>&lt;P&gt;Hey Doug,&lt;/P&gt;&lt;P&gt;I am the Product Manager for th DL languages.&amp;nbsp; I appreciate you bringing this up to the community.&amp;nbsp; We are working to track this with our engineering leads to close the vulnerability in the short-term.&amp;nbsp; We are also working at a better long term strategy.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Oct 2019 19:04:31 GMT</pubDate>
    <dc:creator>Colin_Fallwell</dc:creator>
    <dc:date>2019-10-22T19:04:31Z</dc:date>
    <item>
      <title>Python Agent 4.5.5 contains vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727306#M5701</link>
      <description>&lt;P&gt;Our team has found a vulnerability in the Python agent 4.5.5 version during a scan and are unable to deploy.&amp;nbsp; Has anyone else found this issue?&amp;nbsp; Here is a request from our DevOps team.&lt;/P&gt;&lt;P&gt;Installing the python appdynamics agent 4.5.5.0 pulls in the com.fasterxml.jackson.core_jackson-databind version 2.9.9.1 as a dependency, which includes some critical vulnerabilities (CVSS 9.8) &lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2019-14379" target="_blank" rel="nofollow noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2019-14379&lt;/A&gt;, &lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2019-16335" target="_blank" rel="nofollow noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2019-16335&lt;/A&gt;, and &lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2019-14540" target="_blank" rel="nofollow noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2019-14540&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Could we ask that the next python appdynamics agent update (4.5.6?) use at least com.fasterxml.jackson.core_jackson-databind 2.9.10, which resolves these vulnerabilities.&lt;/P&gt;&lt;P&gt;In our environment we did a “pip install appdynamics”, and a pip list afterwards shows the following versions of the packages installed:&lt;/P&gt;&lt;P&gt;appdynamics&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.5.5.0 &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;appdynamics-bindeps-linux-x64&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;appdynamics-proxysupport-linux-x64 1.8.0.51.1&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 15:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727306#M5701</guid>
      <dc:creator>Doug_Odegaard</dc:creator>
      <dc:date>2019-10-15T15:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Python Agent 4.5.5 contains vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727307#M5702</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.appdynamics.com/t5/user/viewprofilepage/user-id/143601"&gt;@Doug.Odegaard&lt;/A&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;&lt;SPAN&gt;I recommend reporting this to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.appdynamics.com/support/" target="_blank" rel="noopener nofollow noreferrer"&gt;support&lt;/A&gt;&lt;SPAN&gt;. Let me know if you have any trouble with this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2019 17:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727307#M5702</guid>
      <dc:creator>iamryan</dc:creator>
      <dc:date>2019-10-18T17:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Python Agent 4.5.5 contains vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727308#M5703</link>
      <description>&lt;P&gt;Just to let anyone else know the status I am working heavily with support and other channels to get this addressed.&amp;nbsp; In the meantime one can do a pip install but remove the jackson file in question as a workaround but goal is a clean pip install hopefully soon.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 18:41:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727308#M5703</guid>
      <dc:creator>Doug_Odegaard</dc:creator>
      <dc:date>2019-10-22T18:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Python Agent 4.5.5 contains vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727309#M5704</link>
      <description>&lt;P&gt;Hey Doug,&lt;/P&gt;&lt;P&gt;I am the Product Manager for th DL languages.&amp;nbsp; I appreciate you bringing this up to the community.&amp;nbsp; We are working to track this with our engineering leads to close the vulnerability in the short-term.&amp;nbsp; We are also working at a better long term strategy.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 19:04:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Python-Agent-4-5-5-contains-vulnerability/m-p/727309#M5704</guid>
      <dc:creator>Colin_Fallwell</dc:creator>
      <dc:date>2019-10-22T19:04:31Z</dc:date>
    </item>
  </channel>
</rss>

