Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities in dependency com.overzealous:remark:1.1.0 #34

Open
midmarch opened this issue Nov 8, 2022 · 2 comments
Open

Vulnerabilities in dependency com.overzealous:remark:1.1.0 #34

midmarch opened this issue Nov 8, 2022 · 2 comments

Comments

@midmarch
Copy link

midmarch commented Nov 8, 2022

Dependency com.overzealous:remark:1.1.0, declared here:

api('com.overzealous:remark:1.1.0') { transitive = false }

contains multiple vulnerabilities:

  1. CVE-2022-36033
  2. CVE-2021-37714
  3. CVE-2021-29425
  4. CVE-2020-15250

Ref: https://mvnrepository.com/artifact/com.overzealous/remark/1.1.0

@midmarch midmarch changed the title Vulnirabilities in dependency com.overzealous:remark:1.1.0 Vulnerabilities in dependency com.overzealous:remark:1.1.0 Nov 8, 2022
@aalmiray
Copy link
Collaborator

aalmiray commented Nov 8, 2022

The CVES come from jsoup. Latest jsoup (1.15.3) fixes these errors but in a binary incompatible way. Remark (com.kotcrab.remark:remark:1.2.0) has not been updated.

@siboxd
Copy link

siboxd commented Jul 15, 2024

The mentioned dependency is no more present on maven, and any build using your library fails because of it.

Can it be replaced, and a new library version published?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants