Skip to content

Commit 794b293

Browse files
committed
chore(deps): Explicitly set commons-io version to 2.11.0 to avoid older transitive dependency version (CVE-2021-29425)
1 parent 6140f3e commit 794b293

File tree

1 file changed

+10
-0
lines changed
  • aws-serverless-java-container-struts2

1 file changed

+10
-0
lines changed

aws-serverless-java-container-struts2/pom.xml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -87,6 +87,16 @@
8787
</dependency>
8888
</dependencies>
8989

90+
<dependencyManagement>
91+
<dependencies>
92+
<dependency><!-- [CVE-2021-29425] commons-fileupload ships with 2.2 -->
93+
<groupId>commons-io</groupId>
94+
<artifactId>commons-io</artifactId>
95+
<version>2.11.0</version>
96+
</dependency>
97+
</dependencies>
98+
</dependencyManagement>
99+
90100
<build>
91101
<plugins>
92102
<plugin>

0 commit comments

Comments
 (0)