-
Notifications
You must be signed in to change notification settings - Fork 1
Closed
Labels
bugUnwanted / harmful behaviorUnwanted / harmful behavior
Description
Error: Failed to execute goal org.sonatype.ossindex.maven:ossindex-maven-plugin:3.2.0:audit (default-cli) on project import-export-udf-common-scala: Detected 2 vulnerable components:
Error: com.fasterxml.jackson.core:jackson-databind:jar:2.12.7:compile; https://ossindex.sonatype.org/component/pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7?utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error: * [CVE-2022-42003] CWE-502: Deserialization of Untrusted Data (7.5); https://ossindex.sonatype.org/vulnerability/CVE-2022-42003?component-type=maven&component-name=com.fasterxml.jackson.core%2Fjackson-databind&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error: * [CVE-2022-42004] CWE-502: Deserialization of Untrusted Data (7.5); https://ossindex.sonatype.org/vulnerability/CVE-2022-42004?component-type=maven&component-name=com.fasterxml.jackson.core%2Fjackson-databind&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error: org.scala-lang:scala-library:jar:2.13.8:compile; https://ossindex.sonatype.org/component/pkg:maven/org.scala-lang/scala-library@2.13.8?utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error: * [CVE-2022-36944] CWE-502: Deserialization of Untrusted Data (9.8); https://ossindex.sonatype.org/vulnerability/CVE-2022-36944?component-type=maven&component-name=org.scala-lang%2Fscala-library&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Metadata
Metadata
Assignees
Labels
bugUnwanted / harmful behaviorUnwanted / harmful behavior