bugsnag / bugsnag-java

BugSnag error reporting for Java.
https://www.bugsnag.com/platforms/java/
MIT License
56 stars 34 forks source link

Fix reported vulnerabilities #177

Closed RonnyLV closed 2 years ago

RonnyLV commented 2 years ago

Describe the bug

There are a few reported and unfixed vulnerabilities: CVE-2020-36518 CVE-2020-15250

Could you have a look at them?

Steps to reproduce

https://mvnrepository.com/artifact/com.bugsnag/bugsnag/3.6.3

luke-belton commented 2 years ago

Hi @RonnyLV - thanks for raising this, we're going to investigate and will keep this thread updated

smanikim commented 2 years ago

any plan on this one ? @luke-belton

luke-belton commented 2 years ago

Hi @smanikim - just to let you know that we've updated these dependecies, and this was released in v3.6.4 of bugsnag-java 🎉