Skip to content

upgrade to commons-collections.jar 3.2.2 #76

@ndushay

Description

@ndushay

There is a security vulnerability with commons-collections.jar 3.2.1; this code base seems to require it.unimi.dsi:dsiutils:jar:2.0.12 which in turn uses commons-collections:commons-collections:jar:3.2.1 which is vulnerable:

[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ openwayback-cdx-server ---
[INFO] org.netpreserve.openwayback:openwayback-cdx-server:war:2.0.0
[INFO] +- org.netpreserve.commons:webarchive-commons:jar:1.1.4:compile
<snip>
[INFO] |  |  +- commons-collections:commons-collections:jar:3.2.1:compile

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions