Dependency Information
When running clj-watson in a project with
org.clojure/data.fressian {:mvn/version "1.1.1"}
I get the following warning, refering to CVE-2018-10054 (relates to a vulnerability in H2 and its usage in older versions of datomic). I assume this is a false positive.
NAME: org.fressian/fressian
VERSION: 0.6.8
DEPENDENCY FOUND IN:
[org.clojure/data.fressian]
FIX SUGGESTION:
Vulnerabilities
SEVERITY: HIGH
IDENTIFIERS: CVE-2018-10054
CVSS: 8.8 (version 3.1)
PATCHED VERSION: Information not available.