Vulnerability report
Open
dependencies
- Dominant language
- Java
- Stars
- 23.1k
- Forks
- 8.1k
- PR merge metrics
- No merged PRs in 30d
Description
### **Describe the bug**
Provides transitive vulnerable dependency maven:com.alibaba:fastjson:1.2.83_noneautotype
https://github.com/advisories/GHSA-pv7h-hx5h-mgfj 9.8 Deserialization of Untrusted Data vulnerability pending CVSS allocation
For more information please see: [spring-cloud-alibaba-issues](https://github.com/alibaba/spring-cloud-alibaba/issues/3203)
### **Expected behavior**
Upgrade the dependent version to fix the vulnerability.
Contributor guide
Assessment
This issue has not been assessed yet.