aws / aws-lambda-java-libs

Official mirror for interface definitions and helper classes for Java code running on the AWS Lambda platform.

Home Page:https://aws.amazon.com/lambda/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE on aws-lambda-java-serialization

nutzhub opened this issue · comments

Hi I try to use aws-lambda-java-runtime-interface-client but receive the dependency CVE on
aws-lambda-java-serialization-1.0.0.jar (pkg:maven/com.amazonaws/aws-lambda-java-serialization@1.0.0, cpe:2.3:a:amazon:aws_lambda:1.0.0:*:*:*:*:*:*:*) : CVE-2019-10777

Is there a plan to resolve ?

Hi @nutzhub,

This CVE is for a JS command line tool. https://snyk.io/vuln/npm%3Aaws-lambda

I think there might be a mistake in whatever scanning tool you are using.

Could you explain further how you think the aws-lambda-java-runtime-interface-client is effected?

Thanks,

That was a false positive in our CVE scan