There is a vulnerability in SnakeYAML 1.14 ,upgrade recommended
envgap__google__error-prone-1849
01 / FAILURE SIGNATURE
As reported upstream
https://github.com/google/error-prone/blob/569a4c2b6fd203d8701e2e448d283fc794a586d4/docgen/pom.xml#L89-L93
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
569a4c2b6fd203d8701e2e448d283fc794a586d4- Manifest
docgen/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
google/error-prone #1849 · read the original issue
https://github.com/google/error-prone/blob/569a4c2b6fd203d8701e2e448d283fc794a586d4/docgen/pom.xml#L89-L93 CVE-2017-18640 Recommended upgrade version:1.27
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]