IBMStreams/streamsx.objectstorage

Potential security vulnerability in junit.jar

markheger opened this issue · 1 comments

CVE-2020-15250

Solution: upgrade to 4.13.1

<dependency>
    <groupId>junit</groupId>
    <artifactId>junit</artifactId>
    <version>4.13.1</version>
</dependency>

The pom.xml used by JUnit test suite (https://github.com/IBMStreams/streamsx.objectstorage/blob/develop/test/java/com.ibm.streamsx.objectstorage.test/pom.xml) has already the junit 4.13.1 dependency.

For the toolkit release the junit.jar should be deleted in opt/downloaded directory