jmxutils icon indicating copy to clipboard operation
jmxutils copied to clipboard

Bump guava version to 30.0+ to fix CVE-2020-8908

Open parislarkins opened this issue 4 years ago • 0 comments

Hi there,

Our project is using jmxutils and our dependency vulnerability scanning is reporting a Guava vulnerability CVE-2020-8908 that's being brought in by jmxutils. I'm not sure if the project is still active, but is there any possibility the version of Guava could be bumped to resolve this? Because Guava is shaded we can't upgrade the version on our end.

Thanks!

parislarkins avatar Nov 25 '21 00:11 parislarkins