You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@slawekjaranowski Thank you. We will pursue this mitigation technique as an alternative for now. Are there plans for future releases to upgrade the Dom4J package to a non-vulnerable version?
Dom4J 1.6.1 is a transitive dependency of the version plugin and vulnerable to the following:
Versions Maven Plugin – Project Dependencies
org.codehaus.mojo:versions-maven-plugin:maven-plugin:2.16.2
org.apache.maven.doxia:doxia-site-renderer:jar:1.11.1
org.apache.velocity:velocity-tools:jar:2.0
Please upgrade dependency Dom4J 1.6.1 to Dom4J 2.1.3 or higher as the only vulnerability affecting it has been officially withdrawn by the NVD:
The text was updated successfully, but these errors were encountered: