arangodb / arangodb-java-driver

The official ArangoDB Java driver.
Apache License 2.0
200 stars 93 forks source link

Dependency upgrade for vertx to 4.5.3 (CVE-2024-1023) #540

Closed mdmm13 closed 4 months ago

mdmm13 commented 4 months ago

Snyk highlights the recent CVE-2024-1023 DoS vulnerability introduced via the arangodb-spring/java driver's use of vertx. Kindly request the dependency upgrade to 4.5.2 or 4.5.3 to close this given the risk profile.

rashtao commented 4 months ago

Fixed, thanks.