apache / royale-compiler

Apache Royale Compiler
https://royale.apache.org/
Apache License 2.0
95 stars 49 forks source link

Hello, we found a vulnerable dependency in your project #218

Closed JavaEcosystemResearch closed 1 year ago

JavaEcosystemResearch commented 2 years ago

Hi! We spot a vulnerable dependency in your project, which might threaten your software. And we found that the vulnerable function of this CVE can be easily accessed from your software, there is no constraint along the invocation path to the vulnerable function.

Therefore, maybe you need to upgrade this dependency. Hope this can help you! 😄