[Backport 2.x] Fixes CVE-2024-7254 #587
Open
Mend for GitHub.com / Mend Security Check
failed
Dec 10, 2024 in 7m 8s
Security Report
1 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-47535Path to dependency file: /build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/io.netty/netty-common/4.1.114.Final/862712e292b162c8ccaa7847a6a54df8178f77e5/netty-common-4.1.114.Final.jar Dependency Hierarchy: -> netty-codec-http2-4.1.114.Final.jar (Root Library) -> ❌ netty-common-4.1.114.Final.jar (Vulnerable Library) |
Medium | 5.5 | netty-common-4.1.114.Final.jar | Upgrade to version: io.netty:netty-common:4.1.115.Final | None |
Base branch total remaining vulnerabilities: 0
Base branch commit: 4612c6c3d4ee65dfea68c951c314759d6d8ad758
Total libraries scanned: 102
Scan token: dbbcaa42540c449da9e0ef7fe1212333
Loading