There is a vulnerability in log4j 1.2.14,upgrade recommended
Open
area/dashboard
dependencies
good first issue
- Dominant language
- Java
- Stars
- 23.1k
- Forks
- 8.1k
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/alibaba/Sentinel/blob/1f4614c0d4c5e966de1cd9f6715c8220937ef2a9/sentinel-dashboard/pom.xml#L67
CVE-2019-17571 CVE-2020-9488
Recommended upgrade version: 2.0~beta9-1
Contributor guide
Research direction
Start at sentinel-dashboard/pom.xml line 67 and inspect the log4j 1.2.14 dependency in the context of CVE-2019-17571 and CVE-2020-9488. Confirm the recommended replacement version, update the dependency, and verify the Maven build and resolved dependency tree no longer use the vulnerable version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100