Re: Security Vulnerabilities with GWT 2.10

2022-09-01 Thread Thomas Broyer
On Thursday, September 1, 2022 at 11:57:07 AM UTC+2 priyako...@gmail.com wrote: > Thanks for response. > > There is one more CVE has been reported for gwt-dev jar for htmlUnit > component. Details of CVE are as below - > CVE - CVE-2022-29546 > severity - 7.5 > Description - HtmlUnit

Re: Security Vulnerabilities with GWT 2.10

2022-09-01 Thread priyako...@gmail.com
Thanks for response. There is one more CVE has been reported for gwt-dev jar for htmlUnit component. Details of CVE are as below - CVE - CVE-2022-29546 severity - 7.5 Description - HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated

Re: Security Vulnerabilities with GWT 2.10

2022-07-29 Thread Thomas Broyer
On Friday, July 29, 2022 at 1:27:36 PM UTC+2 priyako...@gmail.com wrote: > Hi All, > > Below Security Vulnerabilities in gwt-dev.jar in latest GWT 2.10 release > have been reported by Dependency checker tool - > > [image: gwt-dev_vulnerablities.PNG] > Given above vulnerabilities - > 1. Are

Security Vulnerabilities with GWT 2.10

2022-07-29 Thread priyako...@gmail.com
Hi All, Below Security Vulnerabilities in gwt-dev.jar in latest GWT 2.10 release have been reported by Dependency checker tool - [image: gwt-dev_vulnerablities.PNG] Given above vulnerabilities - 1. Are those security issues addressed in latest 2.10.0 release? 2. If no, is there a plan to