amzn / amzn/fire-app-builder

There is a vulnerability in jackson 2.6.0,upgrade recommended

Open
#67 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
201
Forks
255
PR merge metrics
No merged PRs in 30d

Description

https://github.com/amzn/fire-app-builder/blob/0d940f11151d30a91b49488941ac2a48be6abd7b/Utils/build.gradle#L71

CVE-2020-8840 CVE-2020-9546 CVE-2020-9547 CVE-2020-9548 CVE-2019-14379

Recommended upgrade version:2..3

Contributor guide

Open the contributing guide

Research direction

Start at Utils/build.gradle line 71 and review the Jackson 2.6.0 dependency against the CVEs listed in the issue. Confirm the intended recommended version, which is malformed in the report, then verify that the dependency is upgraded and the project still builds.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.