dropwizard / dropwizard-jdbi

Dropwizard JDBI v2 support
Apache License 2.0
1 stars 7 forks source link

CVE-2020-5245 vulnerability in dropwizard-jdbi-2.0.0 #6

Closed harpreet86 closed 4 years ago

harpreet86 commented 4 years ago

The latest release version for dropwizard-jdbi-2.0.0 is having a vulnerability CVE-2020-5245.

Please suggest.

joschi commented 4 years ago

@harpreet86 Thanks for bringing this up!

You can upgrade to dropwizard-jdbi 2.0.2, which we released today and which should show up on Maven Central with the next sync.