Skip to content

Version 2.2.3.1 contains 5 vulnerabilities in ESAPI dependencies #671

Closed
@cwienands1

Description

@cwienands1

We recently incorporated ESAPI 2.2.3.1 into a number of Spring Boot services. Dependency Checker now flags all those services with a total of 5 vulnerabilities: 3 blocker, 1 critical, 1 major.

The same can be seen in the Maven repository:
https://mvnrepository.com/artifact/org.owasp.esapi/esapi/2.2.3.1

I looked at this project's pom.xml but it looks like these dependencies must be pulled in by the parent pom.

Metadata

Metadata

Assignees

No one assigned

    Labels

    falsepositiveThis issue is a false positive and should not have been made an issue.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions