Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities on DSBulk 1.11.0 #499

Open
dbapramod882 opened this issue Jul 26, 2024 · 1 comment
Open

Vulnerabilities on DSBulk 1.11.0 #499

dbapramod882 opened this issue Jul 26, 2024 · 1 comment

Comments

@dbapramod882
Copy link

Hi Team,

Vulnerabilities detected, in which version can it be resolved.

CVE-2023-44487 Critical dsbulk-1.11.0/lib/netty-codec-http2-4.1.94.Final.jar
CVE-2023-35116 Low dsbulk-1.11.0/lib/jackson-databind-2.13.3.jar
CVE-2024-25710 Low dsbulk-1.11.0/lib/commons-compress-1.21.jar
CVE-2024-26308 Low dsbulk-1.11.0/lib/commons-compress-1.21.jar
CVE-2023-43642 Medium dsbulk-1.11.0/lib/snappy-java-1.1.7.3.jar
CVE-2022-42003 Medium dsbulk-1.11.0/lib/jackson-databind-2.13.3.jar
CVE-2023-5072 Medium dsbulk-1.11.0/lib/json-20220320.jar
CVE-2023-34454 Medium dsbulk-1.11.0/lib/snappy-java-1.1.7.3.jar
CVE-2023-34455 Medium dsbulk-1.11.0/lib/snappy-java-1.1.7.3.jar
CVE-2023-34453 Medium dsbulk-1.11.0/lib/snappy-java-1.1.7.3.jar
CVE-2023-6378 Medium dsbulk-1.11.0/lib/logback-classic-1.2.11.jar
CVE-2022-42004 Medium dsbulk-1.11.0/lib/jackson-databind-2.13.3.jar
CVE-2022-45688 Medium dsbulk-1.11.0/lib/json-20220320.jar

Thanks
Pramod P

@absurdfarce
Copy link
Collaborator

Thanks @dbapramod882 !

I'll note that there are a few things mentioned here that aren't covered in #497

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants