There is a vulnerability in jackson 2.6.0,upgrade recommended
Open
- Dominant language
- Java
- Stars
- 201
- Forks
- 255
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/amzn/fire-app-builder/blob/0d940f11151d30a91b49488941ac2a48be6abd7b/Utils/build.gradle#L71
CVE-2020-8840 CVE-2020-9546 CVE-2020-9547 CVE-2020-9548 CVE-2019-14379
Recommended upgrade version:2..3
Contributor guide
Research direction
Start at Utils/build.gradle line 71 and review the Jackson 2.6.0 dependency against the CVEs listed in the issue. Confirm the intended recommended version, which is malformed in the report, then verify that the dependency is upgraded and the project still builds.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100