adobe / adobe/experience-platform-streaming-connect

CVEs Fix

Open
#78 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
25
Forks
25
PR merge metrics
No merged PRs in 30d

Description

Library | From → To | Findings Cleared
-- | -- | --
commons-codec | 1.11 → 1.18.0 | 1 (BDSA-2012-0001)
commons-lang3 | 3.9 → 3.18.0 | 1 (CVE-2025-48924)
jackson-core | 2.14.0 → 2.21.3 | 4 (CVE-2025-52999, BDSA-2022-4307, BDSA-2025-5555, GHSA-72hv-8253-57qq)
jackson-databind | 2.14.0 → 2.21.3 | Keep aligned with jackson-core via jackson-bom
jackson-databind (CVE-2023-35116) | N/A | Suppress — disputed, no fix exists

Library From → To Findings Cleared
commons-codec 1.11 → 1.18.0 1 (BDSA-2012-0001)
commons-lang3 3.9 → 3.18.0 1 (https://github.com/advisories/GHSA-j288-q9x7-2f5v)
jackson-core 2.14.0 → 2.21.3 4 (https://github.com/advisories/GHSA-h46c-h94j-95f3, BDSA-2022-4307, BDSA-2025-5555, https://github.com/advisories/GHSA-72hv-8253-57qq)
jackson-databind 2.14.0 → 2.21.3 Keep aligned with jackson-core via jackson-bom
jackson-databind (https://github.com/advisories/GHSA-gx6w-fqg7-mc3p) N/A Suppress — disputed, no fix exists

Contributor guide

Open the contributing guide

Research direction

The issue names commons-codec, commons-lang3, jackson-core, jackson-databind, and jackson-bom, but no files or tests. Locate the Java dependency manifest, review the current versions and vulnerability findings, then run the repository's available build or dependency checks. Done means the listed findings are cleared and the disputed jackson-databind finding is suppressed as requested.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.