Re: CVE-2021-26291 in maven-bundle plugin

2023-08-21 Thread Debraj Manna
Any thoughts on this? On Sun, Aug 20, 2023 at 1:01 PM Debraj Manna wrote: > Hi > > In our scan maven-bundle plugin 5.1.5 is getting flagged for > CVE-2021-26291 due to > the presence of maven-compat 3.3.9. I am seeing that the latest version of >

CVE-2021-26291 in maven-bundle plugin

2023-08-20 Thread Debraj Manna
Hi In our scan maven-bundle plugin 5.1.5 is getting flagged for CVE-2021-26291 due to the presence of maven-compat 3.3.9. I am seeing that the latest version of maven-bundle plugin, 5.1.9 is also using maven-compat 3.3.9. Is there any plan to updat