alibaba / alibaba/Sentinel

Vulnerability report

Open
#3,062 0 comments 0 reactions 0 assignees View on GitHub
dependencies
Dominant language
Java
Stars
23.1k
Forks
8.1k
PR merge metrics
No merged PRs in 30d

Description

### **Describe the bug**

Provides transitive vulnerable dependency maven:com.alibaba:fastjson:1.2.83_noneautotype
https://github.com/advisories/GHSA-pv7h-hx5h-mgfj 9.8 Deserialization of Untrusted Data vulnerability pending CVSS allocation

For more information please see: [spring-cloud-alibaba-issues](https://github.com/alibaba/spring-cloud-alibaba/issues/3203)

### **Expected behavior**
Upgrade the dependent version to fix the vulnerability.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.