Open vladmandic opened 2 years ago
Sorry for the delay.
Thank you for your report. We are migrating to a new email-based reporting system in order to better mesh with our internal processes, which will allow us to be more reactive to our users. I have moved your request to the internal tracking system and the research team will look into the issue shortly.
If you notice further issues or would like to follow up on this one, please email ossindex@sonatype.org
Vulnerability URL https://ossindex.sonatype.org/vulnerability/sonatype-2019-0142
Description
however, this vulnerability was fixed long time ago - it clearly states that it only impacts versions 1.6.9 and below and here vulnerability is reported for version 2.10.0!
see for fix confirmation https://github.com/advisories/GHSA-vpq5-4rc8-c222
this seems to be a NEW false-positive as it was not reported for recent versions, so there may be a semver compare mismatch on ossindex side?