There is a vulnerability in ICU for C/C++/Java 55.1,upgrade recommended
Open
Area - Dependencies
Security
- Dominant language
- Java
- Stars
- 14.1k
- Forks
- 3.8k
- Avg merge
- 2d 58m
- Merged PRs (30d)
- 233
Description
https://github.com/apache/druid/blob/52d46cebc31026b8dd39c7d9fb82c62bd77965fb/pom.xml#L419
CVE-2017-17484 CVE-2017-14952 CVE-2016-6293 CVE-2016-7415 CVE-2017-7868 CVE-2017-7867
Recommended upgrade version:
67.1
Contributor guide
Research direction
Start with pom.xml at line 419 and inspect the ICU 55.1 dependency referenced by the issue. Review the listed CVEs and the recommended 67.1 version, then check the project’s dependency validation or build commands. Done means the dependency is upgraded without breaking the build and the vulnerable version is no longer resolved.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100