-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Closed
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file
Description
We have received a notification for a vulnerability in our project using spring-cloud-kubernetes-fabric8-config:jar:3.1.3. Details follow.
Vulnerabilities in: pkg:maven/com.squareup.okhttp3/logging-interceptor@3.12.12 [CVE-2023-0833] (owasp)
+- com.vaadin:control-center-starter:jar:1.0-SNAPSHOT:compile
| \- org.springframework.cloud:spring-cloud-starter-kubernetes-fabric8-config:jar:3.1.3:compile
| \- org.springframework.cloud:spring-cloud-kubernetes-fabric8-config:jar:3.1.3:compile
| +- io.fabric8:kubernetes-client:jar:6.9.2:compile
| | +- io.fabric8:kubernetes-httpclient-okhttp:jar:6.9.2:runtime
| | | \- com.squareup.okhttp3:logging-interceptor:jar:3.12.12:runtime
currently there is not released version from io.fabric8:kubernetes-client with fixes on the reported dependency.
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file