alibaba / alibaba/rpc-benchmark
There is a vulnerability in Spring 4.3.10.RELEASE,upgrade recommended
Open
- Dominant language
- Java
- Stars
- 37
- Forks
- 14
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/alibaba/rpc-benchmark/blob/1c1f649b459e82d5df6445ca81f3b3c67f494e8e/pom.xml#L25
CVE-2018-1270 CVE-2018-1275 CVE-2020-5421
Recommended upgrade version:4.3.29.RELEASE
Contributor guide
No contributing guide indexed for this repository
Research direction
The vulnerable dependency is referenced in pom.xml at line 25; inspect that entry and compare it with the cited CVEs and recommended Spring version. Update the dependency to 4.3.29.RELEASE, then run the repository's existing verification to confirm the project still builds and the vulnerable version is no longer present.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100