genepi / haplogrep3

Free mtDNA Haplogroup Classification Service
https://haplogrep.i-med.ac.at/
MIT License
20 stars 1 forks source link

CVE vulnerability in haplogrep #28

Open JenniferVdL opened 1 year ago

JenniferVdL commented 1 year ago

Hi! during our dependency check the following came along:

One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '9,0': haplogrep-3.2.1.jar: itextpdf-5.1.2.jar: CVE-2022-37109(9.8)

Is it possible to fix this CVE problem? I'm also not sure which dependency uses itextpdf in haplogrep. But perhaps it is possible to upgrade the specific dependency?

With kind regards, Jennifer

seppinho commented 1 year ago

Hi, Looks like this was a code artifact. So it will be completely deleted in the next release. Thanks for pointing us to this.

JenniferVdL commented 1 year ago

Thank you! Can't wait for the next release 😊