Skip to content
This repository has been archived by the owner on Sep 26, 2023. It is now read-only.

Update dependencies to fix several security vulnerabilities #37

Open
albuch opened this issue Jun 30, 2020 · 0 comments
Open

Update dependencies to fix several security vulnerabilities #37

albuch opened this issue Jun 30, 2020 · 0 comments

Comments

@albuch
Copy link
Contributor

albuch commented Jun 30, 2020

The current version of TeamDojo has the following vulnerable dependencies included.

  • org.dom4j_dom4j version 1.6.1 has 2 vulernabilities
  • io.undertow_undertow-core version 1.4.26.Final has 7 vulnerabilities.
  • com.fasterxml.jackson.core_jackson-databind version 2.9.8 has 31 vulnerabilities.
  • com.fasterxml.jackson.core_jackson-databind version 2.9.5 has 42 vulnerabilities.
  • org.apache.logging.log4j_log4j-api version 2.10.0 has 1 vulnerability.

I've tried to provide a pull request, but due to the very outdated and unsupported version of JHipster (v2.1.1) as well as dependencies to other needed upgrades (Gradle, Node-Plugin etc.) I couldn't manage upgrading the stack in a timely manner.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant