[Backport 2.16] Added catch for unexpected inputs. #1447
Mend for GitHub.com / Mend Security Check
failed
Jan 8, 2025 in 2m 42s
Security Report
1 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
| CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
CVE-2024-7254Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.google.protobuf/protobuf-java/3.22.3/fdee98b8f6abab73f146a4edb4c09e56f8278d03/protobuf-java-3.22.3.jar Dependency Hierarchy: -> opensearch-2.16.0-SNAPSHOT.jar (Root Library) -> ❌ protobuf-java-3.22.3.jar (Vulnerable Library) |
7.5 | protobuf-java-3.22.3.jar | Upgrade to version: com.google.protobuf:protobuf-javalite - 3.25.5,4.28.2,4.27.5;com.google.protobuf:protobuf-java - 4.27.5,3.25.5,4.28.2 | None |
Base branch total remaining vulnerabilities: 0
Base branch commit: dca74ce58b638de442f49b06cce78a113c55bc2b
Total libraries scanned: 124
Scan token: d3e179eb13a14c7586981d33b71826db
Loading