Skip to content

CVSS vulnerability detected - can you up-level the offending lib? #326

@jtwing62173

Description

@jtwing62173

Security scans identified an vuln that prevents me from using your cool tool in my org:
Type: VULNERABILITY
Name: SNYK-JAVA-ORGAPACHEMAVENSHARED-570592
CVSS Score v3: 9.8
Severity: severe
Description Link: https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEMAVENSHARED-570592

It's in the org.apache.maven.shared:maven-shared-utils:3.2.1:jar dependency, near as I can tell.

Any chance you can up-level that to a version that doesn't have the vulnerability?

Based on the reporting site, that should be version 3.3.3

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions