Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Jackson databind CVE-2019-14893 due to inclusion of old datatable-dependencies #482

Open
deckaddict opened this issue Dec 12, 2022 · 2 comments

Comments

@deckaddict
Copy link

deckaddict commented Dec 12, 2022

👓 What did you see?

When using tools such as XRay looking for vulnerabilities it triggers on the cucumber-eclipse plugin due to the inclusion of datatable-dependencies version 1.1.7 that is flagged as potentially vulnerable to CVE-2019-14893.

✅ What did you expect to see?

It is preferred to not see any warnings of this type since it is very time consuming to validate if it is a real issue or not for the usage of the tool.

📦 Which tool/library version are you using?

1.0.0.202110280427

🔬 How could we reproduce it?

Given this issue: cucumber/common#679 I believe that it is enough to get up to the latest version of the datatables-dependencies.

📚 Any additional context?

It seems like datatable-dependencies 7.9.0 is the only version that has no known CVEs according:
https://mvnrepository.com/artifact/io.cucumber/datatable/7.9.0

@devisuresh
Copy link

devisuresh commented Jan 14, 2023 via email

@britzl
Copy link

britzl commented Jan 15, 2023

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants