Skip to content

Conversation

@oscerd
Copy link

@oscerd oscerd commented Nov 28, 2025

Updates

  • Affected products
  • Source code location
  • Summary

Comments
Title, version, package, source location

@github-actions github-actions bot changed the base branch from main to oscerd/advisory-improvement-6482 November 28, 2025 14:07
@yhidad31
Copy link

yhidad31 commented Dec 2, 2025

Hello @oscerd, it looks like version 10.3.0 has not yet been published to the Maven registry (see APM Webapp). In order to update the Vulnerable Version Range (VVR) with the fixed version, it needs to be published to the registry. Once the updated version has been uploaded, we can add the fixed version to the VVR.

For now, we can state that the project is vulnerable through version 10.1.0, as that is the latest version uploaded to Maven, and that the fix is available for direct download via the repository link.

Thank you for helping to improve the database.

@advisory-database advisory-database bot merged commit 6748053 into oscerd/advisory-improvement-6482 Dec 5, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @oscerd! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the oscerd-GHSA-v6x2-4q87-rf82 branch December 5, 2025 21:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants