upgrade common-collections / velocity?
Rob Audenaerde
rob.audenaerde at gmail.com
Fri May 12 11:11:28 EDT 2017
Hi all,
I recently started using the owasp maven plugin: dependency-check-maven to
check for vulnerabilities in my projects dependencies. OpenSaml 3.3.0 seems
to use a version of commons-collections with a security advisory. See:
https://nvd.nist.gov/vuln/detail/CVE-2015-6420
[INFO] +- org.opensaml:opensaml-saml-impl:jar:3.3.0:compile
[INFO] | +- org.opensaml:opensaml-security-impl:jar:3.3.0:compile
[INFO] | +- org.opensaml:opensaml-xmlsec-impl:jar:3.3.0:compile
[INFO] | +- org.apache.velocity:velocity:jar:1.7:compile
[INFO] | | +- commons-collections:commons-collections:jar:3.2.1:compile
Need/can the libraries be upgraded?
-Rob
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20170512/7a9db613/attachment.html>
More information about the dev
mailing list