QID 981489
QID 981489: Java (maven) Security Update for org.jooby:jooby (GHSA-px9h-x66r-8mpc)
Security update has been released for io.jooby:jooby,org.jooby:jooby to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Access to sensitive information available from classpath.
Solution
Patched version: 1.6.7 and 2.8.2
Commit 1.x: https://github.com/jooby-project/jooby/commit/34f526028e6cd0652125baa33936ffb6a8a4a009
Commit 2.x: https://github.com/jooby-project/jooby/commit/c81479de67036993f406ccdec23990b44b0bec32Workaround:
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
Commit 1.x: https://github.com/jooby-project/jooby/commit/34f526028e6cd0652125baa33936ffb6a8a4a009
Commit 2.x: https://github.com/jooby-project/jooby/commit/c81479de67036993f406ccdec23990b44b0bec32Workaround:
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
Vendor References
- GHSA-px9h-x66r-8mpc -
github.com/advisories/GHSA-px9h-x66r-8mpc
CVEs related to QID 981489
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-px9h-x66r-8mpc | io.jooby:jooby |
|
|
| GHSA-px9h-x66r-8mpc | org.jooby:jooby |
|