-
Notifications
You must be signed in to change notification settings - Fork 510
Closed
eclipse-jdtls/eclipse.jdt.ls
#3586Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file
Milestone
Description
Vulnerabilities in Dependencies in vscode-java
Description
vscode-java has security vulnerabilities in its dependencies, specifically jsoup . The affected and patched versions are as follows:
1. Jsoup
- Affected versions:
< 1.15.3
- Patched versions:
1.15.3
GitHub Advisory Links
- jsoup: GHSA-gp7f-rwcx-9369
National Vulnerability Database
- jsoup: CVE-2022-36033
Request
Could these dependencies be updated to the patched versions in vscode-java v1.20.0 and above? Thank you.
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file