Description
A test dependency in the main pom.xml has a number of CVEs with a CVSS score as high as 7.5. This is not shipped with the main artefact but will interfere with any corporate approvals process.
Vulnerabilities:
CVE-2024-7885
CVE-2024-6162
CVE-2024-5971
CVE-2024-3653
Cause:
Test Dependency io.undertow:undertow-core 2.2.37.Final
Reference
- https://mvnrepository.com/artifact/com.networknt/json-schema-validator/1.5.3
- https://mvnrepository.com/artifact/io.undertow/undertow-core/2.2.37.Final
- https://github.com/networknt/json-schema-validator/blob/1.5.3/pom.xml#L83