Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix CVE #3381

Merged
merged 1 commit into from
Aug 29, 2024
Merged

Fix CVE #3381

merged 1 commit into from
Aug 29, 2024

Conversation

sbrunner
Copy link
Member

[LOW] com.google.guava:guava@31.1-jre: SNYK-JAVA-COMGOOGLEGUAVA-5710356 CWE-379 [Fixed in: 32.0.0-android, 32.0.0-jre].
[LOW] com.google.guava:guava@31.0.1-jre: SNYK-JAVA-COMGOOGLEGUAVA-5710356 CWE-379 [Fixed in: 32.0.0-android, 32.0.0-jre].
[HIGH] io.airlift:aircompressor@0.20: SNYK-JAVA-IOAIRLIFT-7164637 CWE-125 [Fixed in: 0.27].
[HIGH] org.geotools:gt-main@28.2: SNYK-JAVA-ORGGEOTOOLS-3329308 CWE-89 [Fixed in: 27.5, 28.3].
[MEDIUM] org.springframework:spring-expression@5.3.37: SNYK-JAVA-ORGSPRINGFRAMEWORK-7687446 CWE-770 [Fixed in: 5.3.39].
[MEDIUM] org.springframework:spring-web@5.3.37: SNYK-JAVA-ORGSPRINGFRAMEWORK-7687447 CWE-400 [Fixed in: 5.3.38, 6.0.23, 6.1.12].
[MEDIUM] org.testng:testng@7.5: SNYK-JAVA-ORGTESTNG-3040285 CWE-29 [Fixed in: 7.5.1, 7.7.0].

 [LOW] com.google.guava:guava@31.1-jre: SNYK-JAVA-COMGOOGLEGUAVA-5710356 CWE-379 [Fixed in: 32.0.0-android, 32.0.0-jre].
 [LOW] com.google.guava:guava@31.0.1-jre: SNYK-JAVA-COMGOOGLEGUAVA-5710356 CWE-379 [Fixed in: 32.0.0-android, 32.0.0-jre].
 [HIGH] io.airlift:aircompressor@0.20: SNYK-JAVA-IOAIRLIFT-7164637 CWE-125 [Fixed in: 0.27].
 [HIGH] org.geotools:gt-main@28.2: SNYK-JAVA-ORGGEOTOOLS-3329308 CWE-89 [Fixed in: 27.5, 28.3].
 [MEDIUM] org.springframework:spring-expression@5.3.37: SNYK-JAVA-ORGSPRINGFRAMEWORK-7687446 CWE-770 [Fixed in: 5.3.39].
 [MEDIUM] org.springframework:spring-web@5.3.37: SNYK-JAVA-ORGSPRINGFRAMEWORK-7687447 CWE-400 [Fixed in: 5.3.38, 6.0.23, 6.1.12].
 [MEDIUM] org.testng:testng@7.5: SNYK-JAVA-ORGTESTNG-3040285 CWE-29 [Fixed in: 7.5.1, 7.7.0].
@sbrunner sbrunner closed this Aug 29, 2024
@sbrunner sbrunner deleted the audit-3.30 branch August 29, 2024 16:29
@sbrunner sbrunner restored the audit-3.30 branch August 29, 2024 16:29
@sbrunner sbrunner reopened this Aug 29, 2024
@sbrunner sbrunner marked this pull request as ready for review August 29, 2024 16:29
@sbrunner sbrunner merged commit c0aab78 into 3.30 Aug 29, 2024
13 of 14 checks passed
@sbrunner sbrunner deleted the audit-3.30 branch August 29, 2024 17:40
@geo-ghci-int geo-ghci-int bot added this to the 3.30.7 milestone Sep 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant