Skip to content

Conversation

@chuckaude
Copy link

No description provided.

@chuckaude
Copy link
Author

Automated PR Comment From Polaris SCA

❌ Found dependencies violating policy!

Dependency Policies Violated License(s) Vulnerabilities Short Term Recommended Upgrade Long Term Recommended Upgrade Resolved / Filtered Out
Apache Log4j (org.apache.logging.log4j:log4j-core:2.14.0)
  • Insecure Object Deserialization
  • Expression Language Injection (EL-Injection)
Apache License 2.0 ❌   CVE-2021-44228 Critical CVSS 9.4
❌   CVE-2021-45046 Critical CVSS 9.0
2.25.1 (0 known vulnerabilities) 2.25.1 (0 known vulnerabilities)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants