pinterest / singer

A high-performance, reliable and extensible logging agent for uploading data to Kafka, Pulsar, etc.
Apache License 2.0
182 stars 35 forks source link

vulnerability found in commons-io:commons-io #233

Open JavaEcosystemStudy opened 2 years ago

JavaEcosystemStudy commented 2 years ago

Hi! We spot a vulnerable dependency in your project, which might threaten your software. And we found that the vulnerable function of this CVE can be easily accessed from your software, there is no constraint along the invocation path to the vulnerable function.

Therefore, may be you need to upgrade this dependency. Hope this can help you! 😄

ambud commented 1 year ago

Thanks for reporting this