-
Notifications
You must be signed in to change notification settings - Fork 1.4k
Closed as not planned
Labels
FP ReportossindexLabel for issues that relate to the OSSIndex APILabel for issues that relate to the OSSIndex API
Description
Package URl
pkg:maven/org.apache.commons/[email protected]
CPE
cpe:2.3:a:org.apache.commons:commons-text:1.10.0:::::::*
CVE
ODC Integration
{"label" => "Maven Plugin"}
ODC Version
12.1.9
Description
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API.
That may be so - or not. The CVE is actually for Apple FileMaker which apparently had used commons-text < 1.10. Apart from that, the CVE contains very little information.
Note that you may also bump commons-text to the latest 1.15 for ODC to not report it anymore.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
FP ReportossindexLabel for issues that relate to the OSSIndex APILabel for issues that relate to the OSSIndex API