Skip to content

Conversation

@cycode-security
Copy link

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
pom.xml 1

📂 pom.xml

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
org.apache.commons:commons-lang3 3.4 3.18.0

…mons:commons-lang3 updated to version 3.18.0
@jrsteinebrey
Copy link

jrsteinebrey commented Jul 24, 2025

This fix looks correct to me. This is important to get into this library because it fixes the CVE-2025-48924 https://www.cve.org/CVERecord?id=CVE-2025-48924. One site I read https://www.mend.io/vulnerability-database/CVE-2025-48924?utm_source=JetBrains rated the severity score as HIGH (8.6)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants