sonatype-lift[bot] commented on a change in pull request #585:
URL: https://github.com/apache/solr/pull/585#discussion_r803155178



##########
File path: solr/modules/s3-repository/build.gradle
##########
@@ -39,6 +39,10 @@ dependencies {
     runtimeOnly (group: 'com.fasterxml.woodstox', name: 'woodstox-core')
     runtimeOnly (group: 'org.codehaus.woodstox', name: 'stax2-api')
 
+    implementation 'org.springframework.boot:spring-boot'
+    implementation 'org.springframework:spring-core'

Review comment:
       *Severe OSS Vulnerability:*
   ### pkg:maven/org.springframework/spring-core@5.3.9
   0 Critical, 1 Severe, 0 Moderate, 0 Unknown vulnerabilities have been found 
across 1 dependencies
   
   <details>
     <summary><b>Components</b></summary><br/>
     <ul>
         <details>
           
<summary><b>pkg:maven/org.springframework/spring-core@5.3.9</b></summary>
           <ul>
     <details>
       <summary><b>SEVERE Vulnerabilities (1)</b></summary><br/>
   <ul>
   
   > #### [CVE-2021-22096] In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 
5.2.17, and older unsupport...
   > In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older 
unsupported versions, it is possible for a user to provide malicious input to 
cause the insertion of additional log entries.
   >
   > **CVSS Score:** 4.3
   >
   > **CVSS Vector:** CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
   
   </ul>
       </details>
           </ul>
         </details>
     </ul>
   </details>
   (at-me [in a reply](https://help.sonatype.com/lift/talking-to-lift) with 
`help` or `ignore`)




-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org
For additional commands, e-mail: issues-h...@solr.apache.org

Reply via email to