Skip to content

Conversation

@joelhof
Copy link

@joelhof joelhof commented Sep 29, 2021

As stated in issue #452 servo version 0.10.1 has several CVE issues reported, see output from dependencyCheck plugin below.
Upgrading to 0.13.2 removes these CVE warnings.

servo-core-0.10.1.jar (pkg:maven/com.netflix.servo/[email protected], cpe:2.3:a:docker:docker:0.10.1:::::::, cpe:2.3:a:travis-ci:travis_ci:0.10.1:::::::) : CVE-2014-0047, CVE-2014-0048, CVE-2014-5277, CVE-2014-5278, CVE-2014-5282, CVE-2014-6407, CVE-2014-8178, CVE-2014-8179, CVE-2014-9356, CVE-2014-9358, CVE-2015-3627, CVE-2015-3630, CVE-2015-3631, CVE-2016-3697, CVE-2017-14992, CVE-2019-13139, CVE-2019-13509, CVE-2019-15752, CVE-2019-16884, CVE-2019-5736, CVE-2020-27534, CVE-2021-21284, CVE-2021-21285, CVE-2021-3162
servo-internal-0.10.1.jar (pkg:maven/com.netflix.servo/[email protected], cpe:2.3:a:docker:docker:0.10.1:::::::, cpe:2.3:a:travis-ci:travis_ci:0.10.1:::::::) : CVE-2014-0047, CVE-2014-0048, CVE-2014-5277, CVE-2014-5278, CVE-2014-5282, CVE-2014-6407, CVE-2014-8178, CVE-2014-8179, CVE-2014-9356, CVE-2014-9358, CVE-2015-3627, CVE-2015-3630, CVE-2015-3631, CVE-2016-3697, CVE-2017-14992, CVE-2019-13139, CVE-2019-13509, CVE-2019-15752, CVE-2019-16884, CVE-2019-5736, CVE-2020-27534, CVE-2021-21284, CVE-2021-21285, CVE-2021-3162

Version 0.10.1 has several reported CVE, as stated in issue 452.
@wojteo wojteo mentioned this pull request Nov 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant