Skip to content

[MNG-7513] Address commons-io_commons-io vulnerability found in maven latest version #9273

@jira-importer

Description

@jira-importer

Polu Ram Charan Teja opened MNG-7513 and commented

In the maven latest version 3.8.6 one dependency is identified with known vulnerabilities in commons-io-2.6.jar CVE-2021-29425. so please suggest if you have plan to upgrade commons-io to latest version as we are getting impacted due to security checks


Affects: 3.8.6

Issue Links:

  • MNG-7533 jar v2.6 has medium (CVE-2021-29425) Prisma vulnerability associated with maven v3.8.6
    ("is duplicated by")

Remote Links:

Backported to: 4.0.0-alpha-2, 3.9.0, 3.8.7

0 votes, 5 watchers

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions