Fix CVE dependency issue(Dependency org.apache.commons:commons-compress, leading to CVE problem) #19
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi, In /meecrowave-maven-plugin,there is a dependency org.apache.commons:commons-compress:1.18 that calls the risk method.
CVE-2019-12402
The scope of this CVE affected version is [1.15,1.19)
After further analysis, in this project, the main Api called is org.apache.commons.compress.archivers.zip.NioZipEncoding: encode(java.lang.String)Ljava.nio.ByteBuffer
Risk method repair link : GitHub
CVE Bug Invocation Path--
Path Length : 5
CVE-2021-36090
The scope of this CVE affected version is [0,1.31)
After further analysis, in this project, the main Api called is org.apache.commons.compress.archivers.zip.AsiExtraField: parseFromLocalFileData(byte[],int,int)V
Risk method repair link : GitHub
CVE Bug Invocation Path--
Path Length : 8
Dependency tree--
Suggested solutions:
Update dependency version @struberg
Thank you very much.