BetterCloud / vault-java-driver

Zero-dependency Java client for HashiCorp's Vault
https://bettercloud.github.io/vault-java-driver/
334 stars 224 forks source link

AppScan on Cloud shows two vulnerabilites #218

Open jstoeff opened 4 years ago

jstoeff commented 4 years ago

Our project is using vault-java-driver 3.1.0. Latest scan with Tool "AppScan on Cloud" shows two vulnerabilites (see attached report) asoc_audit-persistence_fixedOpenSourdeFindings_20200316_11_53_58.pdf . I compared the source code with latest 5.1.0 and it looks like the affected code did not change siginificantly since 3.1.0. May be these issues are worth a fix because for enterprise customers vulnerabilities are a real problem.