Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Transitive vulnerable dependency #262

Closed
palhoye opened this issue Mar 11, 2024 · 1 comment
Closed

Transitive vulnerable dependency #262

palhoye opened this issue Mar 11, 2024 · 1 comment
Labels
type: dependency-upgrade A dependency upgrade
Milestone

Comments

@palhoye
Copy link

palhoye commented Mar 11, 2024

Checkmarx reports the following transitive vulnerability via Gradle for "io.zonky.test:embedded-database-spring-test:2.5.0":

Provides transitive vulnerable dependency maven:org.apache.commons:commons-compress:1.24.0

  • CVE-2024-26308 7.5 Allocation of Resources Without Limits or Throttling vulnerability with High severity found
  • CVE-2024-25710 5.5 Loop with Unreachable Exit Condition ("Infinite Loop") vulnerability with Medium severity found
@tomix26
Copy link
Collaborator

tomix26 commented Mar 18, 2024

Thank you for the report. The fix has just been merged into the affected library here: zonkyio/embedded-postgres#128

@tomix26 tomix26 added this to the 2.5.1 milestone Mar 18, 2024
@tomix26 tomix26 added the type: dependency-upgrade A dependency upgrade label Mar 18, 2024
@tomix26 tomix26 closed this as completed Apr 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: dependency-upgrade A dependency upgrade
Projects
None yet
Development

No branches or pull requests

2 participants