# Liquibse 3.8.0 vulnerabilities

**URL:** <https://forum.liquibase.org/t/liquibse-3-8-0-vulnerabilities/4356>\
**Category:** Liquibase Development\
**Created:** [June 25, 2020, 2:29pm UTC](https://forum.liquibase.org/t/liquibse-3-8-0-vulnerabilities/4356 "2020-06-25T14:29:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![AnantdevPathak](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@AnantdevPathak](https://forum.liquibase.org/u/AnantdevPathak)\
**Post date:** [June 25, 2020, 2:29pm UTC](https://forum.liquibase.org/t/liquibse-3-8-0-vulnerabilities/4356/1 "2020-06-25T14:29:46Z")

</div>

Hi,

Below URL says some vulnerabilities in liquibase version 3.8.0.

> <https://github.com/jeremylong/DependencyCheck/issues/2169>
>
> Facing below vulnerabilities in owasp dependency check.
> \[ERROR\] One or more dependencies were identified with vulnerabilities: 
> \[ERROR\] 
> \[ERROR\] liquibase-core-3.8.0.jar: bootstrap.js: CVE-2018-14042, CVE-2019-8331,...

Is this vulnerabilities fixed in version 3.10.0?

Thanks and Regards,  
Anantdev

---

<div class="post-metadata">

**Author:** ![ronak](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/ronak/32/221_2.png) [@ronak](https://forum.liquibase.org/u/ronak)\
**Post date:** [June 29, 2020, 10:11pm UTC](https://forum.liquibase.org/t/liquibse-3-8-0-vulnerabilities/4356/2 "2020-06-29T22:11:29Z")

</div>

Hi @AnantdevPathak,

I am hoping we will be adding known vulnerabilities to our release notes, but to answer your question:

> ERROR] One or more dependencies were identified with vulnerabilities:  
> [ERROR]  
> [ERROR] liquibase-core-3.8.0.jar: bootstrap.js: CVE-2018-14042, CVE-2019-8331, CVE-2018-14041, CVE-2018-14040  
> [ERROR] liquibase-core-3.8.0.jar: bootstrap.min.js: CVE-2018-14042, CVE-2019-8331, CVE-2018-14041, CVE-2018-14040  
> [ERROR] liquibase-core-3.8.0.jar: jquery-1.11.0.min.js: CVE-2015-9251, CVE-2019-11358  
> [ERROR]  
> [ERROR] See the dependency-check report for more details.
> 
> ```auto
> 
> ```

We can’t see bootstrap.js, bootstrap.min.js, or jquery-1.11 after 3.8.6, so looks like those won’t trip vulnerability scans.

Thanks,

Ronak
