Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Various CVE are reported: CVE-2024-7254, sonatype-2024-0639 #352

Open
yeikel opened this issue Oct 1, 2024 · 1 comment
Open

Various CVE are reported: CVE-2024-7254, sonatype-2024-0639 #352

yeikel opened this issue Oct 1, 2024 · 1 comment

Comments

@yeikel
Copy link

yeikel commented Oct 1, 2024

Hi team,

I tried to pull this dependency but the following CVEs are reported that prevent me from doing so:

CVE-2024-7254
sonatype-2024-0639

Could you please fix this?

@yeikel yeikel changed the title Fix CVE-2023-2976 Fix CVE-2023-2976, CVE-2023-34453, CVE-2023-34454, CVE-2023-34455 , CVE-2024-7254, sonatype-2024-0639 Oct 2, 2024
@yeikel yeikel changed the title Fix CVE-2023-2976, CVE-2023-34453, CVE-2023-34454, CVE-2023-34455 , CVE-2024-7254, sonatype-2024-0639 Various CVE are reported: CVE-2023-2976, CVE-2023-34453, CVE-2023-34454, CVE-2023-34455 , CVE-2024-7254, sonatype-2024-0639 Oct 2, 2024
@yeikel
Copy link
Author

yeikel commented Oct 9, 2024

It seems that the latest release fixed many of the vulnerabilities. Now only the following are pending

9 Security-High High risk CVSS score Found security vulnerability CVE-2024-7254 with severity >= 7 (severity = 8.7)Found security vulnerability CVE-2024-7254 with severity < 9 (severity = 8.7)
9 Security-High High risk CVSS score Found security vulnerability sonatype-2024-0639 with severity >= 7 (severity = 7.5)Found security vulnerability sonatype-2024-0639 with severity < 9 (severity = 7.5)

@yeikel yeikel changed the title Various CVE are reported: CVE-2023-2976, CVE-2023-34453, CVE-2023-34454, CVE-2023-34455 , CVE-2024-7254, sonatype-2024-0639 Various CVE are reported: CVE-2024-7254, sonatype-2024-0639 Oct 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant