-
Notifications
You must be signed in to change notification settings - Fork 2.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Critical CVE-2024-1597 in dependencies #2216
Comments
where is this a dependency ? |
In the POM. |
It's only used for testing it is not shipped in the jar |
Ah, yes, I see that. It's listed as a "Vulnerability from dependencies" for HikariCP, but because it's just a test dependency, doesn't seem to show as a vulnerability for downstream projects. |
Well you can always create a PR |
I think I can do it, if the PR only requires upgrading the version |
There is a current dependency on postgresql v42.5.1. That version has a critical CVE ( CVE-2024-1597 ). The issue is fixed in patch version 42.5.5 (and in other minor versions).
The text was updated successfully, but these errors were encountered: