[ https://issues.apache.org/jira/browse/MDEP-531?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Christian Schulte closed MDEP-531. ---------------------------------- Resolution: Fixed > MDP 2.10 depends on a known insecure library commons-collections:3.2.1 > ---------------------------------------------------------------------- > > Key: MDEP-531 > URL: https://issues.apache.org/jira/browse/MDEP-531 > Project: Maven Dependency Plugin > Issue Type: Bug > Affects Versions: 2.10 > Reporter: Paul Farrar > Assignee: Christian Schulte > Fix For: 3.0 > > > org.apache.maven.plugins:maven-dependency-plugin:2.10 has the following > dependency: > {code} > <dependency> > <groupId>commons-collections</groupId> > <artifactId>commons-collections</artifactId> > <version>3.2.1</version> > </dependency> > {code} > This version of commons-collections has a known severe security vulnerability: > https://www.kb.cert.org/vuls/id/576313 > https://commons.apache.org/proper/commons-collections/security-reports.html > Please upgrade to a newer version of commons-collections as the insecure > version is blocked for my usage. -- This message was sent by Atlassian JIRA (v6.3.4#6332)