alibaba / alibaba/DataX

There is a vulnerability in fastjson 1.2.68 ,upgrade recommended

Open
#865 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
17.4k
Forks
5.7k
PR merge metrics
No merged PRs in 30d

Description

https://github.com/alibaba/DataX/blob/aafcac8a0b3aa3b777ae5947f13f233411fd362a/opentsdbreader/pom.xml#L28

CVE-2020-8840
Recommended upgrade version:1.2.29.sec10

Contributor guide

No contributing guide indexed for this repository

Research direction

Start at opentsdbreader/pom.xml line 28 and review the fastjson dependency associated with CVE-2020-8840. Update it to the recommended secure version 1.2.29.sec10, then confirm the dependency declaration no longer uses the vulnerable version.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.