Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Gradle has snakeyaml dependency, which reported to have a CVE with critical base score #24883

Closed
WilsonNeo opened this issue Apr 24, 2023 · 2 comments
Assignees
Labels
closed:duplicate Duplicated or superseeded by another issue

Comments

@WilsonNeo
Copy link

Expected Behavior

Expected no critical vulnerability findings.

Current Behavior

A critical vulnerability was detected regarding the snakeyaml dependency in the latest version of Gradle, https://nvd.nist.gov/vuln/detail/CVE-2022-1471#range-9042833

Due to vulnerability finding, the docker image we are building, which contains gradle, is deem to be a vulnerable image.
May we expect a patch or rc soon to fix this vulnerability?

Context (optional)

No response

Steps to Reproduce

I executed the Trivy container scanner to scan a docker image built with the latest Gradle. The vulnerability was reported in its security report.

Gradle version

8.1.1

Build scan URL (optional)

No response

Your Environment (optional)

No response

@JamieMagee
Copy link

Fixed in #25011

@ljacomet ljacomet modified the milestone: 8.2 RC1 May 15, 2023
@ljacomet
Copy link
Member

Thank you for your interest in Gradle!

This issue will be closed as a duplicate of


I forgot this issue had been filed when upgrading the library.

Thanks for the report, but please in the future prefer security@gradle.com for such reports, just in case the vulnerability is exploitable.

@ljacomet ljacomet closed this as not planned Won't fix, can't repro, duplicate, stale May 15, 2023
@ljacomet ljacomet added closed:duplicate Duplicated or superseeded by another issue and removed a:bug to-triage labels May 15, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
closed:duplicate Duplicated or superseeded by another issue
Projects
None yet
Development

No branches or pull requests

3 participants