Hi, there is a new CVE issue published on 18th of February on io.netty dependencies. I just integrated graphql-kotlin to our backend project and started to get security warnings. More information for CVE https://snyk.io/vuln/SNYK-JAVA-ORGWSO2TRANSPORTHTTP-548944 . Any suggestion is appreciated.
sevil
02/28/2020, 11:05 AM
The dependency causing the problem added by org.springframework.bootspring boot starter reactor netty2.2.4.RELEASE which comes with org.springframework.bootspring boot starter webflux2.2.4.RELEASE