Details
-
Task
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
Apache Sling Testing Clients 3.0.10
-
None
Description
Sling testing clients are using com.google.guava guava 14.0.1 which is vulnerable to CVE-2018-10237(MEDIUM) [1] and CVE-2020-8908(LOW) [2].
Mitigation: remove the guava dependency.
[1] https://www.cvedetails.com/cve/CVE-2018-10237/
[2] https://www.cvedetails.com/cve/CVE-2020-8908/