Skip to content
This repository has been archived by the owner on Oct 9, 2024. It is now read-only.

Hello! We found a vulnerable dependency in your project. Are you aware of it? #5

Open
HelloMavenEco opened this issue Aug 23, 2022 · 0 comments

Comments

@HelloMavenEco
Copy link

Hi! We spot a vulnerable dependency in your project, which might threaten your software.
And we found that the vulnerable function of this CVE can be easily accessed from your software.

  • CVE_ID: CVE-2021-29425
  • Vulnerable dependency: commons-io:commons-io
  • Your invocation path to the vulnerable method:
com.mediaworx.mojo.opencms.AbstractOpenCmsMojo:attachFolder(java.lang.String,java.lang.String,java.io.File)
⬇️
org.apache.commons.io.FilenameUtils:normalize(java.lang.String)
⬇️
org.apache.commons.io.FilenameUtils:doNormalize(java.lang.String,char,boolean)
⬇️
org.apache.commons.io.FilenameUtils:getPrefixLength(java.lang.String)

Therefore, maybe you need to upgrade this dependency. Hope this can help you! 😄

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant