Open
Description
Plugin contains Apache Software Foundation Commons Compress 1.21 that has 2 known vulnerabilities affecting endpoints.
CVE-2024-25710 - https://nvd.nist.gov/vuln/detail/CVE-2024-25710
CVE-2024-26308 - https://nvd.nist.gov/vuln/detail/CVE-2024-26308
Can the library be updated to Commons Compress 1.27+?
https://mvnrepository.com/artifact/org.apache.commons/commons-compress
This continually comes up in our vulnerability checks.
Metadata
Metadata
Assignees
Labels
No labels