Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .security/known_cves.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,4 +22,8 @@
The Dumper is a CLI app, not a public-facing web server. It does not accept or process arbitrary URIs from untrusted
external users. The attack vector for CVE-2024-6763 requires an attacker to supply
a malformed URI to be parsed by the server; The Dumper does not expose an interface for such input.
- CVE: CVE-2025-0982
artifact: cpe:2.3:a:google:application_integration:8.2.1
justification: >
False Positive. In February 2025, Google Cloud stopped supporting Rhino engine. Which is the cause of the vulnerability

Loading