apache / apache/maven-release

Maven release version 3.3.1 contains org.apache.sshd:sshd-common:2.7.0 with CVE 2022-45047

Open
#1,458 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
128
Forks
145
Avg merge
7h 7m
Merged PRs (30d)
3

Description

### New feature, improvement proposal

I want to use the release plugin (latest 3.3.1), but when I try our company CVE scanner goes off on a critical CVE in one of it's transitive dependencies and blocks it.
org.apache.sshd:sshd-common:2.7.0
CVE 2022-45047
Can this dependency chain be updated?

Contributor guide

No contributing guide indexed for this repository

Research direction

No files or tests are named in the issue. Start by tracing the Maven release plugin 3.3.1 dependency chain that resolves org.apache.sshd:sshd-common:2.7.0, then check how the dependency version is declared and managed. Done means the release plugin no longer brings in the CVE-2022-45047 version and the dependency scan passes.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.