Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-42889 #1250

Closed
antoniivanov opened this issue Oct 20, 2022 · 0 comments · Fixed by #1255
Closed

CVE-2022-42889 #1250

antoniivanov opened this issue Oct 20, 2022 · 0 comments · Fixed by #1255
Labels
area/control-service bug Something isn't working

Comments

@antoniivanov
Copy link
Collaborator

antoniivanov commented Oct 20, 2022

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42889

Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

https://github.com/vmware/versatile-data-kit/blob/main/projects/control-service/projects/versions-of-external-dependencies.gradle#L44

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/control-service bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant