exasol / exasol-virtual-schema-lua

Virtual Schema from Exasol to Exasol implemented in Lua
MIT License
1 stars 1 forks source link

Fix CVE-2023-42503 in test dependency `org.apache.commons:commons-compress` #45

Closed kaklakariada closed 11 months ago

kaklakariada commented 11 months ago
Error:  Failed to execute goal org.sonatype.ossindex.maven:ossindex-maven-plugin:3.2.0:audit (default-cli) on project exasol-virtual-schema-lua: Detected 1 vulnerable components:
Error:    org.apache.commons:commons-compress:jar:1.23.0:test; https://ossindex.sonatype.org/component/pkg:maven/org.apache.commons/commons-compress@1.23.0?utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error:      * [CVE-2023-42503] CWE-20: Improper Input Validation (5.5); https://ossindex.sonatype.org/vulnerability/CVE-2023-42503?component-type=maven&component-name=org.apache.commons%2Fcommons-compress&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1