apache / apache/drill

CVE-2020-8908 in Guava v.28.2-jre, should upgrade to v.30.1.1

Open
#2,260 8 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
2k
Forks
990
Avg merge
1d 8h
Merged PRs (30d)
5

Description

**Describe the bug**
CVE-2020-8908 in Guava v.28.2-jre, should upgrade to v.30.1.1

**To Reproduce**
Please check vulnerability section in :
[https://github.com/google/guava/issues/4011](https://github.com/google/guava/issues/4011)

**Expected behavior**
Upgrading to v30.1.1 will mitigate this vulnerability.

**Screenshots**
If applicable, add screenshots to help explain your problem.

**Desktop (please complete the following information):**
- OS: all
- Browser all
- Version all

**Smartphone (please complete the following information):**
- Device: [e.g. iPhone6]
- OS: [e.g. iOS8.1]
- Browser [e.g. stock browser, safari]
- Version [e.g. 22]

**Additional context**
Add any other context about the problem here.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.