salesforce-marketingcloud / FuelSDK-Java

Salesforce Marketing Cloud Java SDK
BSD 3-Clause "New" or "Revised" License
72 stars 123 forks source link

Please consider upgrading three dependencies to mitigate several known CVEs #100

Open sethb3214 opened 5 years ago

sethb3214 commented 5 years ago

Dependency vulnerability analysis shows that there are three dependencies in this project that appear to contain known CVEs. The dependencies are

Here are the Bouncy Castle CVEs:

Here are the Apache CXF Transport CVEs:

Here is the WS Security CVE:

While these libraries don't appear to be used by the Java FuelSDK, is it possible to upgrade these dependencies to a more secure version?