apache / apache/cloudberry

PXF 2.0 using Spring-Boot ecosystem component dependencies - Security vulnerability

Open
#1,805 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
1.4k
Forks
247
Avg merge
4d 3h
Merged PRs (30d)
39

Description

@tuhaihe Regarding PXF2.0, seems like using Spring Boot 2.5.12 ecosystem framework:

Is PXF built using Spring Boot 2.5.12 ecosystem components?

If yes, can this be patched to latest version (OR) removed, to make it supported by PXF avoiding vulnerabilities ?

I can see multiple Sprin-boot components:

spring-boot-gradle-plugin-2.5.12.jar
spring-boot-starter-web-2.5.12.jar
spring-boot-starter-tomcat-2.5.12.jar
spring-boot-actuator-2.5.12.jar
spring-boot-autoconfigure-2.5.12.jar

Contributor guide

Open the contributing guide

Research direction

Start by locating the dependency declarations for the listed Spring Boot 2.5.12 components, including spring-boot-starter-web, spring-boot-starter-tomcat, spring-boot-actuator, and spring-boot-autoconfigure. Check which versions are supported and affected, then confirm whether the dependencies can be upgraded or removed without breaking PXF.

Written by the indexing model from the issue text.

Assessment

Tech stack
spring-boot
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.