exasol / virtual-schema-common-jdbc

Common module for JDBC-based access from Virtual Schemas
MIT License
0 stars 1 forks source link

Dependency check fails with vulnerability in `org.apache.derby:derby` #154

Closed kaklakariada closed 9 months ago

kaklakariada commented 9 months ago
Error:  Failed to execute goal org.sonatype.ossindex.maven:ossindex-maven-plugin:3.2.0:audit (default-cli) on project virtual-schema-common-jdbc: Detected 1 vulnerable components:
Error:    org.apache.derby:derby:jar:10.15.2.0:test; https://ossindex.sonatype.org/component/pkg:maven/org.apache.derby/derby@10.15.2.0?utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error:      * [CVE-2022-46337] CWE-94: Improper Control of Generation of Code ('Code Injection') (4.2); https://ossindex.sonatype.org/vulnerability/CVE-2022-46337?component-type=maven&component-name=org.apache.derby%2Fderby&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1