embedded-redis
embedded-redis copied to clipboard
Security - Upgrade to commons-io 2.8.0 to resolve CVE-2021-29425
Embedded Redis is currently using version 2.5 of commons-io. This has the following vulnerability (CVSS score 5.3) - https://nvd.nist.gov/vuln/detail/CVE-2021-29425
Upgrading to 2.7 or higher resolves this.
Second this - our project has flagged the above CVE due to use of this package.
need this too :/
This repo is up-to-date https://github.com/codemonstur/embedded-redis