apache / apache/ignite

because of vulnerability scanning ,H2 version of 1.4.197 , how to upgrade ?

Open
#11,265 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
5.1k
Forks
1.9k
Avg merge
3d 2h
Merged PRs (30d)
46

Description

Is there a plan to upgrade to version h2 or other evasion methods, as there is a remote execution vulnerability (CVE-2021-42392) in the latest version of gnite (2.16.0) using h2 (1.4.197)?

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the H2 dependency used by Ignite 2.16.0 and the reported CVE-2021-42392 details. Determine whether a supported H2 upgrade or documented mitigation is possible, then verify that the vulnerability is addressed without breaking Ignite compatibility.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
databases, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.