[GH-15865] Upgrade org.python:jython to CWE-416 of com.github.jnr:jnr-posix (overriding org.python.core.imp class from Jython with custom changes, search for CUSTOM CHANGE) #15866
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #15865
See #15865 for the details about problem.
jnr-posix
is not reported by gradle as other transitive dependencies, but with the upgrade of Jython to 2.7.3, we get the following fromMETA-INF/maven/com.github.jnr/jnr-posix/pom.properties
of h2o.jarThe version jnr-posix:3.1.15 shouldn't suffer from the vulnerability. (https://security.snyk.io/vuln/SNYK-JAVA-COMGITHUBJNR-1570422)