Skip to content

Vulnerabilities in guava dependency #25

@Canos

Description

@Canos

As you can see in this page.
https://mvnrepository.com/artifact/io.kraken.client/client/1.1.2

Guava version dependency is very old (2014) and has a couple of security vulnerabilities.

I dont know how hard is to upgrade this dependency, but security should be a priority.

The issues are
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8908
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10237

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions