apache / apache/druid

There is a vulnerability in ICU for C/C++/Java 55.1,upgrade recommended

Open
#10,633 1 comment 0 reactions 0 assignees View on GitHub
Area - Dependencies Security
Dominant language
Java
Stars
14.1k
Forks
3.8k
Avg merge
2d 58m
Merged PRs (30d)
233

Description

https://github.com/apache/druid/blob/52d46cebc31026b8dd39c7d9fb82c62bd77965fb/pom.xml#L419

CVE-2017-17484 CVE-2017-14952 CVE-2016-6293 CVE-2016-7415 CVE-2017-7868 CVE-2017-7867

Recommended upgrade version:
67.1

Contributor guide

Open the contributing guide

Research direction

Start with pom.xml at line 419 and inspect the ICU 55.1 dependency referenced by the issue. Review the listed CVEs and the recommended 67.1 version, then check the project’s dependency validation or build commands. Done means the dependency is upgraded without breaking the build and the vulnerable version is no longer resolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.