← All tasks
javamock-server/mockserver-monorepo #1544Not a task: not reproduced

mockserver-netty@5.14.0 loading wrong version from rhino and having CVEs

envgap__mock-server__mockserver-monorepo-1544

01 / FAILURE SIGNATURE

As reported upstream

4. What error you saw:
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
b607ad690543b17a6f6d6ecd92292ca3f28afe0d
Manifest
mockserver-core/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

mock-server/mockserver-monorepo #1544 · read the original issue
**Describe the issue**

When using the mockserver-netty@5.14.0, I'm having vulnerability issue reported.



**What you are trying to do**

mockserver-netty@5.14.0



**MockServer version**

The version you are using (i.e. 5.14.0)



**To Reproduce**

Run some vulnerability check.



1. How you are running MockServer (i.e maven plugin, docker, etc) gradle

3. Code you used to create expectations. none

4. What error you saw:

```log

Issues with no direct upgrade or patch:

  ✗ XML External Entity (XXE) Injection 

[High Severity][https://snyk.io/vuln/SNYK-JAVA-ORGMOZILLA-1314295] in org.mozilla:rhino@1.7.7.2

    

introduced by org.mock-server:mockserver-netty@5.14.0 > org.mock-server:mockserver-core@5.14.0 > 

io.swagger.parser.v3:swagger-parser@2.1.2 > io.swagger.parser.v3:swagger-parser-v2-converter@2.1.2 > 

io.swagger:swagger-compat-spec-parser@1.0.61 > com.github.java-json-tools:json-schema-validator@2.2.14 > 

com.github.java-json-tools:json-schema-core@1.2.14 > org.mozilla:rhino@1.7.7.2 and 3 other path(s)

  This issue was fixed in versions: 1.7.12

```



**Expected behaviour**

I saw that on the parent pom.xml, this was supposed to be fixed but it seems not.

```xml

 <!-- open api -->

        <dependency>

            <groupId>io.swagger.parser.v3</groupId>

            <artifactId>swagger-parser</artifactId>

            <version>2.1.7</version>

            <exclusions>

                <exclusion>

                    <groupId>com.github.fge</groupId>

                    <artifactId>json-patch</artifactId>

                </exclusion>

                <exclusion>

                    <groupId>javax.validation</groupId>

                    <artifactId>validation-api</artifactId>

                </exclusion>

            </exclusions>

        </dependency>

        <!-- used by swagger-parser force version due to CVEs -->

        <dependency>

            <groupId>org.mozilla</groupId>

            <artifactId>rhino</artifactId>

            <version>1.7.14</version>

        </dependency>

```



```log

+--- org.mock-server:mockserver-netty:5.14.0

|    +--- org.mock-server:mockserver-client-java:5.14.0

|    |    +--- org.mock-server:mockserver-core:5.14.0

|    |    |    +--- io.swagger.parser.v3:swagger-parser:2.1.2

|    |    |    |    +--- io.swagger.parser.v3:swagger-parser-v2-converter:2.1.2

|    |    |    |    |    +--- io.swagger:swagger-compat-spec-parser:1.0.61

|    |    |    |    |    |    +--- com.github.java-json-tools:json-schema-validator:2.2.14

|    |    |    |    |    |    |    +--- com.github.java-json-tools:json-schema-core:1.2.14

|    |    |    |    |    |    |    |    +--- org.mozilla:rhino:1.7.7.2

```

**MockServer Log**

Log output, as INFO level (or lower)

Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]