{"id":2145,"date":"2021-07-14T06:53:55","date_gmt":"2021-07-14T06:53:55","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/use-user-libraries-without-security-vulnerabilities\/"},"modified":"2022-01-26T15:01:07","modified_gmt":"2022-01-26T15:01:07","slug":"securityjarvulnerability","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityjarvulnerability","title":{"rendered":"Use user libraries without security vulnerabilities"},"content":{"rendered":"\n<p id=\"block-65feb11c-fc9e-472a-822a-29fbdc9f4864\">Introduced in version 2.6 (released August 2021)<\/p>\n\n\n\n<p>We introduced a new feature called <a href=\"https:\/\/sdf-docs.clevr.com\/docs\/acr\/java-libraries\/\" data-type=\"docs\" data-id=\"2201\">Java Libraries<\/a>. Now ACR reviews the user libraries in your application against known vulnerabilities. This rule reports vulnerabilities above a configurable level as violations. By default, all vulnerabilities classified as high or critical are reported as violations. <\/p>\n\n\n\n<p>You find more information on the actual security vulnerability in our <em>Java libraries<\/em> feature:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"525\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/01\/image-1-1024x525.png\" alt=\"\" class=\"wp-image-2374\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/01\/image-1-980x502.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/01\/image-1-480x246.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><figcaption>Violation overview with an arrow pointing to java libraries feature.<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":27,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-2145","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2145"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2145"}],"version-history":[{"count":3,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2145\/revisions"}],"predecessor-version":[{"id":2375,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2145\/revisions\/2375"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"REST calls with templates should be escaped","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityrestwithtemplate","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2860"}],"prev":[{"title":"Users should be signed in with a maximum of one session","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityallowonesessionperuser","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1594"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2145"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=2145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}