apache / apache/hugegraph-toolchain

Provides transitive vulnerable dependency maven:org.apache.commons:commons-text:1.9

Open
#541 1 comment 0 reactions 0 assignees View on GitHub
dependencies security
Dominant language
Java
Stars
121
Forks
125
Avg merge
10d 10h
Merged PRs (30d)
3

Description

### Bug Type (问题类型)

rest-api (结果不合预期)

### Before submit

- [X] 我已经确认现有的 [Issues](https://github.com/apache/hugegraph/issues) 与 [FAQ](https://hugegraph.apache.org/docs/guides/faq/) 中没有相同 / 重复问题 (I have confirmed and searched that there are no similar problems in the historical issue and documents)

### Environment (环境信息)

版本1.0

### Expected & Actual behavior (期望与实际表现)

```

org.apache.hugegraph
hugegraph-client
1.0.0

```
这个版本提示
```
Provides transitive vulnerable dependency maven:org.apache.commons:commons-text:1.9
CVE-2022-42889 9.8 Improper Control of Generation of Code ('Code Injection') vulnerability
```

经过查询,是个洞

### Vertex/Edge example (问题点 / 边数据举例)

_No response_

### Schema [VertexLabel, EdgeLabel, IndexLabel] (元数据结构)

_No response_

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by tracing the hugegraph-client Maven dependency configuration to find why org.apache.commons:commons-text:1.9 is brought in transitively. Confirm the dependency resolves to a version without CVE-2022-42889 and verify the Maven dependency or security scan no longer reports the vulnerable version.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.