alibaba / alibaba/rpc-benchmark

There is a vulnerability in Spring 4.3.10.RELEASE,upgrade recommended

Open
#3 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
37
Forks
14
PR merge metrics
No merged PRs in 30d

Description

https://github.com/alibaba/rpc-benchmark/blob/1c1f649b459e82d5df6445ca81f3b3c67f494e8e/pom.xml#L25

CVE-2018-1270 CVE-2018-1275 CVE-2020-5421
Recommended upgrade version:4.3.29.RELEASE

Contributor guide

No contributing guide indexed for this repository

Research direction

The vulnerable dependency is referenced in pom.xml at line 25; inspect that entry and compare it with the cited CVEs and recommended Spring version. Update the dependency to 4.3.29.RELEASE, then run the repository's existing verification to confirm the project still builds and the vulnerable version is no longer present.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.