Maven release version 3.3.1 contains org.apache.sshd:sshd-common:2.7.0 with CVE 2022-45047
- Dominant language
- Java
- Stars
- 128
- Forks
- 145
- Avg merge
- 7h 7m
- Merged PRs (30d)
- 3
Description
### New feature, improvement proposal
I want to use the release plugin (latest 3.3.1), but when I try our company CVE scanner goes off on a critical CVE in one of it's transitive dependencies and blocks it.
org.apache.sshd:sshd-common:2.7.0
CVE 2022-45047
Can this dependency chain be updated?
Contributor guide
No contributing guide indexed for this repository
Research direction
No files or tests are named in the issue. Start by tracing the Maven release plugin 3.3.1 dependency chain that resolves org.apache.sshd:sshd-common:2.7.0, then check how the dependency version is declared and managed. Done means the release plugin no longer brings in the CVE-2022-45047 version and the dependency scan passes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100