← All tasks
javadropwizard/dropwizard #4091Not a task: already works

"Improper Input Validation" security risk through dropwizard-validation > jakarta.el

envgap__dropwizard__dropwizard-4091

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
4c8fb51cc7b8ce7e16444f16a422e2e484424bc0
Manifest
dropwizard-dependencies/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

dropwizard/dropwizard #4091 · read the original issue
In the latest version [2.0.23](https://github.com/dropwizard/dropwizard/releases/tag/v2.0.23) our security scanner highlights a new critical security risk through:



```

io.dropwizard:dropwizard-core@2.0.22 > 

io.dropwizard:dropwizard-validation@2.0.22 > 

org.glassfish:jakarta.el@3.0.3

```



* [Snyk database](https://app.snyk.io/vuln/SNYK-JAVA-ORGGLASSFISH-1297098)

* [Potentially related Issue at Jakarta.EL](https://github.com/eclipse-ee4j/el-ri/issues/155)

* [Offending library](https://mvnrepository.com/artifact/jakarta.el/jakarta.el-api/3.0.3)



There is no direct upgrade path available as of today unfortunately. The issue has not been fixed in Jakarta EL 4.0.0. 

But it should be included once it's fixed in the original project.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]