Update dependency com.microsoft.azure:azure to v1.29.0 #486
Mend for GitHub.com / WhiteSource Security Check
failed
Mar 3, 2024 in 2m 47s
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-3635Path to dependency file: /commons/pac-batch-commons/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.15.0/okio-1.15.0.jar Dependency Hierarchy: -> azure-1.29.0.jar (Root Library) -> azure-client-runtime-1.7.0.jar -> client-runtime-1.7.0.jar -> retrofit-2.5.0.jar -> okhttp-3.12.6.jar -> ❌ okio-1.15.0.jar (Vulnerable Library) |
High | 7.5 | okio-1.15.0.jar | Upgrade to version: com.squareup.okio:okio-jvm:3.4.0 | #445 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2023-3635 | okio-1.14.0.jar |
CVE-2018-1000850 | retrofit-2.4.0.jar |
Base branch total remaining vulnerabilities: 457
Base branch commit: acf9a0620c1a37cee4f2896d71e1c3731c5c7b06
Total libraries scanned: 377
Scan token: e4d3f09f561544c8b90e9b59ebe32727
Loading