
APrieto034095 (Community Member) asked a question.
Hi,
Veracode SCA analysis detected a medium vulnerability on the hibernate-validator-4.3.2.Final.jar component. Looking at the CVE (CVE-2014-3558), the description says: "... hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2 ...". How does Veracode detect a vulnerability on that component if the CVE marked it as a safe one?
.png)
Thank you for your patience @APrieto034095 (Community Member) . This version of hibernate-validator has now been marked as not vulnerable and I have verified that your results reflect this.
Please let me know if you have any remaining questions or concerns.
Thank you,
Boy Baukema