Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix for vunerabilities reported by snky #1121

Merged
merged 2 commits into from
Nov 24, 2019
Merged

Conversation

velo
Copy link
Member

@velo velo commented Nov 24, 2019

No description provided.

Vulnerable module: io.netty:netty-codec-http
Introduced through: io.reactivex:[email protected] and io.reactivex:[email protected]
Exploit maturity: No known exploit
Vulnerable module: com.google.guava:guava
Introduced through: com.netflix.ribbon:[email protected] and com.netflix.ribbon:[email protected]
Exploit maturity: No known exploit

https://app.snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-32236
@velo velo merged commit 2087d4b into OpenFeign:master Nov 24, 2019
@velo velo deleted the vunerabilities branch November 24, 2019 20:59
velo added a commit that referenced this pull request Oct 7, 2024
* Fix for HTTP Request Smuggling
Vulnerable module: io.netty:netty-codec-http
Introduced through: io.reactivex:[email protected] and io.reactivex:[email protected]
Exploit maturity: No known exploit

* Fix for Deserialization of Untrusted Data
Vulnerable module: com.google.guava:guava
Introduced through: com.netflix.ribbon:[email protected] and com.netflix.ribbon:[email protected]
Exploit maturity: No known exploit

https://app.snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-32236
velo added a commit that referenced this pull request Oct 8, 2024
* Fix for HTTP Request Smuggling
Vulnerable module: io.netty:netty-codec-http
Introduced through: io.reactivex:[email protected] and io.reactivex:[email protected]
Exploit maturity: No known exploit

* Fix for Deserialization of Untrusted Data
Vulnerable module: com.google.guava:guava
Introduced through: com.netflix.ribbon:[email protected] and com.netflix.ribbon:[email protected]
Exploit maturity: No known exploit

https://app.snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-32236
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant