Skip to content

[CVEs] Critical and High CEVs reported on PMD and PMD dependencies #4691

@eugenepugach

Description

@eugenepugach

Affects PMD Version:
7.0.0-rc3

Description:
Hello PMD team. We scanned PMD source code with Snyk and another system it reported 2 critical and 1 high CVEs.
Also this vulnerabilities block deployment and creating Docker image and another servers:

Vulnerable Library: scala-reflect-2.13.3.jar (/dist/pmd-bin/lib/scala-reflect-2.13.3.jar)

Dependency Hierarchy:

Directly - ⚠️ scala-reflect-2.13.3.jar (Vulnerability Library)

Severity:
🚫 CRITICAL
CVE-2022-36944

Fixed Version:
♻️ scala-reflect-2.13.9.jar


Vulnerable Library: scala-reflect-2.13.3.jar (/dist/pmd-bin/lib/scala-reflect-2.13.3.jar)

Dependency Hierarchy:

Directly - ⚠️ scala-reflect-2.13.3.jar (Vulnerability Library)

Severity:
🚫 CRITICAL
VULNDB-298991

Fixed Version:
♻️ scala-reflect-2.13.9.jar


Vulnerable Library: commons-io (/dist/pmd-bin/lib/pmd-ui-7.0.0-rc1.jar:commons-io)

Dependency Hierarchy:

  • ⚠️ pmd-ui-7.0.0-rc1.jar (Root Library)
  • ⚠️ commons-io (Vulnerability Library)

Severity:
🚫 HIGH
VULNDB-239195

Fixed Version:
♻️ commons-io-2.8.0.jar

Metadata

Metadata

Assignees

No one assigned

    Labels

    a:bugPMD crashes or fails to analyse a file.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions