[ https://issues.apache.org/jira/browse/THRIFT-5512?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17488981#comment-17488981 ]
Jens Geyer edited comment on THRIFT-5512 at 2/8/22, 4:16 PM: ------------------------------------------------------------- {quote}Consider fixing the dep versions and doing a minor release. {quote} Consider sending a pull request. Or updating your deps manually. was (Author: jensg): {quote}Consider fixing the dep versions and doing a minor release.{quote} Consider sending a pull request. > CVEs notified on Maven Central (through deps) > --------------------------------------------- > > Key: THRIFT-5512 > URL: https://issues.apache.org/jira/browse/THRIFT-5512 > Project: Thrift > Issue Type: Bug > Affects Versions: 0.15.0 > Reporter: Divye Kapoor > Priority: Minor > > Consider fixing the dep versions and doing a minor release. > Maven central identifies indirect CVEs: > https://mvnrepository.com/artifact/org.apache.thrift/libthrift/0.15.0 -- This message was sent by Atlassian Jira (v8.20.1#820001)