You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hey, one of our internal security scans reported Apache commons-configuration version 1.10 used in eureka client library, this version has the following vulnerabilities : CVE-2024-29133, BDSA-2024-0705.
Any particular reason we are not considering an upgrade for this dependency?
The text was updated successfully, but these errors were encountered:
Gautham-JS
changed the title
Eureka client using very old version of apache commons-configuration.
Eureka client using vulnerable version of apache commons-configuration.
May 6, 2024
@Gautham-JS It looks like this vulnerability was actually brought in from commons-configuration:commons-configuration:1.0-rc1 . The recommendation is currently to upgrade to the 2.10.1 version.
[Vendor] team discovered that [CVE-2024-29133] was actually introduced in version 1.0-rc1 of the commons-configuration package instead of the version 2.0.0 of the commons-configuration2 package as stated in the advisory.
Hey, one of our internal security scans reported Apache commons-configuration version 1.10 used in eureka client library, this version has the following vulnerabilities : CVE-2024-29133, BDSA-2024-0705.
Any particular reason we are not considering an upgrade for this dependency?
The text was updated successfully, but these errors were encountered: