Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-41915 affecting dependency maven:io.netty:netty-codec:4.1.85.Final #68

Open
john-latham opened this issue Jan 22, 2023 · 3 comments

Comments

@john-latham
Copy link

IntelliJ reports, for the dependency com.pusher:pusher-http-java:1.3.3:


Provides transitive vulnerable dependency maven:io.netty:netty-codec:4.1.85.Final

CVE-2022-41915 6.5 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability with medium severity found
https://devhub.checkmarx.com/cve-details/CVE-2022-41915

Results powered by Checkmarx(c)

@benjamin-tang-pusher
Copy link
Contributor

Hi, thanks for bringing this to our attention. I will take a look at the dependency.

@stale
Copy link

stale bot commented Jun 10, 2023

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. If you'd like this issue to stay open please leave a comment indicating how this issue is affecting you. Thank you.

@stale stale bot added the wontfix label Jun 10, 2023
@john-latham
Copy link
Author

Security vulnerability should not be closed as stale. Please re-open.

@stale stale bot removed the wontfix label Jun 10, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants