Skip to content

Vulnerable Dependencies #489

@ghost

Description

The following dependencies / versions have open CVEs against them:

  • com.squareup.okhttp3 : logging-interceptor @ 3.8.1

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20200 (disputed, see square/okhttp#4967)

  • org.java-websocket : Java-WebSocket @ 1.3.8 (

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11050

  • org.msgpack : msgpack-core @ 0.8.16

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-5234 (probably not relevant as against C# implementation)

  • io.netty : netty-transport @ 4.1.34.Final

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-16869
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-20444
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-20445
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11612

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions