Skip to content

Commit caf1938

Browse files
committed
chore(deps): Explicitly set commons-io version to 2.11.0 to avoid older transitive dependency version (CVE-2021-29425)
1 parent 7294aad commit caf1938

File tree

1 file changed

+10
-0
lines changed
  • aws-serverless-java-container-core

1 file changed

+10
-0
lines changed

aws-serverless-java-container-core/pom.xml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -101,6 +101,16 @@
101101
</dependency>
102102
</dependencies>
103103

104+
<dependencyManagement>
105+
<dependencies>
106+
<dependency><!-- [CVE-2021-29425] commons-fileupload ships with 2.2 -->
107+
<groupId>commons-io</groupId>
108+
<artifactId>commons-io</artifactId>
109+
<version>2.11.0</version>
110+
</dependency>
111+
</dependencies>
112+
</dependencyManagement>
113+
104114
<build>
105115
<plugins>
106116
<plugin>

0 commit comments

Comments
 (0)