Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Are both these jars required or only one needed also 1.3.33 version has vulunerabilities reported #575

Open
nagkumar opened this issue May 30, 2023 · 1 comment

Comments

@nagkumar
Copy link

   implementation("org.jsmart:zerocode-tdd:1.3.33")
    implementation("org.jsmart:zerocode-tdd-jupiter:1.3.33")
@nagkumar nagkumar changed the title ARe both these jars required or only one needed Are both these jars required or only one needed May 30, 2023
@nagkumar
Copy link
Author

image

Provides transitive vulnerable dependency maven:ch.qos.logback:logback-core:1.0.7
CVE-2017-5929 9.8 Deserialization of Untrusted Data vulnerability pending CVSS allocation
CVE-2021-42550 6.6 Deserialization of Untrusted Data vulnerability pending CVSS allocation
Results powered by Checkmarx(c)

@nagkumar nagkumar changed the title Are both these jars required or only one needed Are both these jars required or only one needed also 1.3.33 version has vulunerabilities reported May 30, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant