exasol / error-code-crawler-maven-plugin

Validator and crawler for exasol-error-codes in Java code
MIT License
1 stars 1 forks source link

ossindex-maven-plugin report vulnerabilities in dependencies #74

Closed kaklakariada closed 2 years ago

kaklakariada commented 2 years ago
 Error:  Failed to execute goal org.sonatype.ossindex.maven:ossindex-maven-plugin:3.1.0:audit (default-cli) on project error-code-crawler-maven-plugin: Detected 2 vulnerable components:
Error:    com.fasterxml.jackson.core:jackson-databind:jar:2.13.0:compile; https://ossindex.sonatype.org/component/pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.0?utm_source=ossindex-client&utm_medium=integration&utm_content=1.1.1
Error:      * [CVE-2020-36518] CWE-787: Out-of-bounds Write (7.5); https://ossindex.sonatype.org/vulnerability/CVE-2020-36518?component-type=maven&component-name=com.fasterxml.jackson.core%2Fjackson-databind&utm_source=ossindex-client&utm_medium=integration&utm_content=1.1.1
Error:      * 1 vulnerability found (7.5); https://ossindex.sonatype.org/vulnerability/sonatype-2021-4682
Error:    org.apache.maven:maven-artifact-manager:jar:2.2.1:provided; https://ossindex.sonatype.org/component/pkg:maven/org.apache.maven/maven-artifact-manager@2.2.1?utm_source=ossindex-client&utm_medium=integration&utm_content=1.1.1
Error:      * [CVE-2021-26291] CWE-346: Origin Validation Error (9.1); https://ossindex.sonatype.org/vulnerability/CVE-2021-26291?component-type=maven&component-name=org.apache.maven%2Fmaven-artifact-manager&utm_source=ossindex-client&utm_medium=integration&utm_content=1.1.1