Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Two vulnerabilities CVE-2020-8908(3.3), CVE-2023-2976(7.1) #109

Closed
WTKersten opened this issue Nov 14, 2024 · 2 comments
Closed

Two vulnerabilities CVE-2020-8908(3.3), CVE-2023-2976(7.1) #109

WTKersten opened this issue Nov 14, 2024 · 2 comments

Comments

@WTKersten
Copy link

Describe the security issue

The depency com.google.guava 30.0-jre is vulnerable to CVE-2020-8908(3.3), CVE-2023-2976(7.1)

Upgrading to 32.0-jre or more recent should resolve the issue.

Additional context

No response

@WTKersten
Copy link
Author

See there's already a pull request for it, can this be merged?

#105

@WTKersten WTKersten reopened this Nov 14, 2024
@8naama
Copy link
Contributor

8naama commented Dec 31, 2024

Thank you @WTKersten for bringing this to our attention!
We've addressed the reported vulnerability and released a new version with the updated package version

@8naama 8naama closed this as completed Dec 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants