Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-43138 and org.clojure/core.async #140

Closed
fdabrao opened this issue Apr 19, 2022 · 3 comments
Closed

CVE-2021-43138 and org.clojure/core.async #140

fdabrao opened this issue Apr 19, 2022 · 3 comments

Comments

@fdabrao
Copy link

fdabrao commented Apr 19, 2022

Hello,

I've got this security problem that is pointing out to https://github.com/caolan/async vulnerability.
image
Is that a false positive?

Thank you

@vemv
Copy link
Collaborator

vemv commented Apr 19, 2022

Hi, thanks for the report!

What nvd-clojure version are you using?

@fdabrao
Copy link
Author

fdabrao commented Apr 19, 2022

The last one {:mvn/version "RELEASE"}, at this moment -> v2.5.0

@vemv
Copy link
Collaborator

vemv commented Apr 19, 2022

Thanks!

Indeed it's a false positive. Thanks for reporting it in jeremylong/DependencyCheck#4384.

In the meantime you can add it to your suppressions .xml file, there's doc/examples that can be found in the readme.

Cheers - V

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants