Project

General

Profile

Actions

Bug #19425

closed

False-positive vulnerability in cve dependencies

Added by Alexis Mousset almost 3 years ago. Updated over 2 years ago.

Status:
Released
Priority:
N/A
Category:
Packaging
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:

Description

The detected vulnerability is:

refined_2.13-0.9.20.jar: CVE-2021-34364

which affects a browser extension (https://github.com/sindresorhus/refined-github) and not a scala lib (https://github.com/fthomas/refined)

Actions #1

Updated by Alexis Mousset almost 3 years ago

  • Project changed from Rudder tools to Rudder plugins
  • Category set to Packaging
  • Assignee set to Alexis Mousset
  • Target version changed from master to 6.1
Actions #2

Updated by Alexis Mousset almost 3 years ago

  • Status changed from New to In progress
Actions #3

Updated by Alexis Mousset almost 3 years ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Alexis Mousset to François ARMAND
  • Pull Request set to https://github.com/Normation/rudder-plugins-private/pull/181
Actions #4

Updated by Alexis Mousset almost 3 years ago

  • Status changed from Pending technical review to Pending release

Applied in changeset rudder-plugins-private:commit:rudder-plugins-private|78b17624c38b6fe312a713c2894ba071f7b28535.

Actions #5

Updated by Vincent MEMBRÉ over 2 years ago

  • Status changed from Pending release to Released
Actions

Also available in: Atom PDF