Hi, @wsargent , @shipkit-org , I'd like to report a vulnerability issue in com.tersesystems.blacklite:blacklite-codec-zstd:1.1.0.
Issue Description
I noticed that com.tersesystems.blacklite:blacklite-codec-zstd:1.1.0 directly depends on com.github.luben:zstd-jni:v1.4.5-6 in the pom. However, as shown in the following dependency graph, com.github.luben:zstd-jni:v1.4.5-6 sufferes from the vulnerability which the C library zstd(version:1.4.5) exposed: CVE-2021-24032.
Dependency Graph between Java and Shared Libraries
![image (12)](https://user-images.githubusercontent.com/103260963/163192714-3f4c9742-90b0-449e-8fc5-2a51be9f23c2.png)
Suggested Vulnerability Patch Versions
com.github.luben:zstd-jni:v1.4.9-1 (>=v1.4.9-1) has upgraded this vulnerable C library zstd
to the patch version 1.4.9.
Java build tools cannot report vulnerable C libraries, which may induce potential security issues to many downstream Java projects. Could you please upgrade this vulnerable dependency?
Thanks for your help~
Best regards,
Helen Parr