[jira] [Commented] (ZOOKEEPER-4510) dependency-check:check failing - reload4j-1.2.19.jar: CVE-2020-9493, CVE-2022-23307

2022-05-04 Thread Mohammad Arshad (Jira)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-4510?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17531892#comment-17531892 ] Mohammad Arshad commented on ZOOKEEPER-4510: dependency-check-maven upgrade to latest

[jira] [Commented] (ZOOKEEPER-4510) dependency-check:check failing - reload4j-1.2.19.jar: CVE-2020-9493, CVE-2022-23307

2022-04-11 Thread Mohammad Arshad (Jira)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-4510?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17520474#comment-17520474 ] Mohammad Arshad commented on ZOOKEEPER-4510: As CVE false positive issue resolution is

[jira] [Commented] (ZOOKEEPER-4510) dependency-check:check failing - reload4j-1.2.19.jar: CVE-2020-9493, CVE-2022-23307

2022-04-05 Thread Mohammad Arshad (Jira)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-4510?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17517849#comment-17517849 ] Mohammad Arshad commented on ZOOKEEPER-4510: Thanks [~c...@qos.ch] for the good

[jira] [Commented] (ZOOKEEPER-4510) dependency-check:check failing - reload4j-1.2.19.jar: CVE-2020-9493, CVE-2022-23307

2022-04-05 Thread Jira
[ https://issues.apache.org/jira/browse/ZOOKEEPER-4510?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17517718#comment-17517718 ] Ceki Gülcü commented on ZOOKEEPER-4510: --- I suggest that this false positive be reported at

[jira] [Commented] (ZOOKEEPER-4510) dependency-check:check failing - reload4j-1.2.19.jar: CVE-2020-9493, CVE-2022-23307

2022-04-05 Thread Mohammad Arshad (Jira)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-4510?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17517660#comment-17517660 ] Mohammad Arshad commented on ZOOKEEPER-4510: you are right, I can see both the CVEs are

[jira] [Commented] (ZOOKEEPER-4510) dependency-check:check failing - reload4j-1.2.19.jar: CVE-2020-9493, CVE-2022-23307

2022-04-05 Thread Christopher Tubbs (Jira)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-4510?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17517491#comment-17517491 ] Christopher Tubbs commented on ZOOKEEPER-4510: -- 1.2.19 is the latest version right now