Skip to content

Upgrade commons-text-1.9.jar #892

Closed
Closed
@datenimperator

Description

@datenimperator

Describe the bug
The VScode extension pivotal.vscode-spring-boot-1.40.0 includes the file language-server\BOOT-INF\lib\commons-text-1.9.jar. A critical security issue is reported as CVE-2022-42889 for this release. This error has been fixed in releases 1.10.0 and higher.

Please update the dependency to one not vulnerable.

To Reproduce

  • Install the current extension "Pivotal Spring Boot Tools" on VScode.
  • Inspect the contents of the path %HOME%\.vscode\extensions\pivotal.vscode-spring-boot-1.40.0\language-server\BOOT-INF\lib to find the vulnerable jar file.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions