False alert - Arbitrary Code Execution vulnerability in org.keycloak:keycloak-saml-core

Resolves #14639
This commit is contained in:
Bruno Oliveira da Silva 2022-09-28 12:20:26 -03:00
parent 20fa75f677
commit db34e9e2ce

7
.github/snyk/.snyk vendored
View file

@ -52,6 +52,13 @@ ignore:
More details:
- https://github.com/keycloak/keycloak/security/advisories/GHSA-mwm4-5qwr-g9pf
- https://access.redhat.com/security/cve/cve-2021-3424
SNYK-JAVA-ORGKEYCLOAK-2987457:
- "*":
reason: >
Keycloak is no longer vulnerable. The issue was fixed on Keycloak 19.0.2
More details:
- https://github.com/keycloak/keycloak/security/advisories/GHSA-wf7g-7h6h-678v
- https://access.redhat.com/security/cve/CVE-2022-2668
# License warnings
snyk:lic:maven:org.eclipse.sisu:org.eclipse.sisu.plexus:EPL-1.0:
- "*":