apache / apache/hertzbeat

[BUG] Vulnerabilites in version 1.6.0

Open
#2,797 0 comments 1 reaction 0 assignees View on GitHub
bug discussion good first issue
Dominant language
Java
Stars
7.4k
Forks
1.3k
Avg merge
1d 20h
Merged PRs (30d)
32

Description

### Is there an existing issue for this?

- [X] I have searched the existing issues

### Current Behavior

[hertzbeat.csv](https://github.com/user-attachments/files/17568925/hertzbeat.csv)

In order to use any tool, we have to run through scan in our organization and attached are the list of vulnerabilities identified in version 1.6.0.

### Expected Behavior

_No response_

### Steps To Reproduce

_No response_

### Environment

```markdown
HertzBeat version(s):1.6.0
```

### Debug logs

_No response_

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by opening the attached hertzbeat.csv and reviewing the vulnerabilities reported for HertzBeat version 1.6.0. Trace each listed item to the affected project component and existing dependency or configuration, then verify that the reported vulnerabilities are addressed; the issue does not name specific files or tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.