"Improper Input Validation" security risk through dropwizard-validation > jakarta.el
envgap__dropwizard__dropwizard-4091
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
4c8fb51cc7b8ce7e16444f16a422e2e484424bc0- Manifest
dropwizard-dependencies/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
dropwizard/dropwizard #4091 · read the original issue
In the latest version [2.0.23](https://github.com/dropwizard/dropwizard/releases/tag/v2.0.23) our security scanner highlights a new critical security risk through: ``` io.dropwizard:dropwizard-core@2.0.22 > io.dropwizard:dropwizard-validation@2.0.22 > org.glassfish:jakarta.el@3.0.3 ``` * [Snyk database](https://app.snyk.io/vuln/SNYK-JAVA-ORGGLASSFISH-1297098) * [Potentially related Issue at Jakarta.EL](https://github.com/eclipse-ee4j/el-ri/issues/155) * [Offending library](https://mvnrepository.com/artifact/jakarta.el/jakarta.el-api/3.0.3) There is no direct upgrade path available as of today unfortunately. The issue has not been fixed in Jakarta EL 4.0.0. But it should be included once it's fixed in the original project.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]