upgrade common-collections / velocity?

Rob Audenaerde rob.audenaerde at gmail.com
Fri May 12 11:11:28 EDT 2017


Hi all,

I recently started using the owasp maven plugin: dependency-check-maven to
check for vulnerabilities in my projects dependencies. OpenSaml 3.3.0 seems
to use a version of commons-collections with a security advisory. See:

https://nvd.nist.gov/vuln/detail/CVE-2015-6420

[INFO] +- org.opensaml:opensaml-saml-impl:jar:3.3.0:compile
[INFO] |  +- org.opensaml:opensaml-security-impl:jar:3.3.0:compile
[INFO] |  +- org.opensaml:opensaml-xmlsec-impl:jar:3.3.0:compile
[INFO] |  +- org.apache.velocity:velocity:jar:1.7:compile
[INFO] |  |  +- commons-collections:commons-collections:jar:3.2.1:compile

Need/can the libraries be upgraded?

-Rob
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20170512/7a9db613/attachment.html>


More information about the dev mailing list