exasol / exasol-virtual-schema

Virtual Schema from Exasol to Exasol
MIT License
1 stars 2 forks source link

Fix security issue in Postgres driver dependency #74

Closed kaklakariada closed 2 years ago

kaklakariada commented 2 years ago

See CVE-2022-21724 in the PostgreSQL JDBC driver.

 Error:  Failed to execute goal org.sonatype.ossindex.maven:ossindex-maven-plugin:3.2.0:audit (default-cli) on project exasol-virtual-schema: Detected 1 vulnerable components:
Error:    org.postgresql:postgresql:jar:42.3.2:test; https://ossindex.sonatype.org/component/pkg:maven/org.postgresql/postgresql@42.3.2?utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error:      * [CVE-2022-26520] ** DISPUTED ** In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL o... (9.8); https://ossindex.sonatype.org/vulnerability/b3cceadf-d8e7-4549-a4bf-a0c25624053a?component-type=maven&component-name=org.postgresql.postgresql&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1

See https://github.com/exasol/test-db-builder-java/issues/97