[ https://issues.apache.org/jira/browse/SLING-12492?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Eric Norman resolved SLING-12492. --------------------------------- Resolution: Fixed Merged PR #16 at: [{{98644ce}}|https://github.com/apache/sling-org-apache-sling-scripting-javascript/commit/98644ce4d3ac39e81607237bf932f47848ec3d96] > Apache Sling Scripting JavaScript 3.1.4 is affected by vulnerabilities > CVE-2022-32549 and CVE-2021-29425. > --------------------------------------------------------------------------------------------------------- > > Key: SLING-12492 > URL: https://issues.apache.org/jira/browse/SLING-12492 > Project: Sling > Issue Type: Improvement > Components: Scripting > Affects Versions: Scripting JavaScript 3.1.4 > Reporter: Scott Yuan > Assignee: Eric Norman > Priority: Minor > Fix For: Scripting JavaScript 3.1.6 > > > The MVN Repository reports that the latest release, Apache Sling Scripting > JavaScript 3.1.4, is affected by vulnerabilities CVE-2022-32549 and > CVE-2021-29425 due to outdated dependencies. For more details, visit MVN > Repository. -- This message was sent by Atlassian Jira (v8.20.10#820010)