because of vulnerability scanning ,H2 version of 1.4.197 , how to upgrade ?
Open
- Dominant language
- Java
- Stars
- 5.1k
- Forks
- 1.9k
- Avg merge
- 3d 2h
- Merged PRs (30d)
- 46
Description
Is there a plan to upgrade to version h2 or other evasion methods, as there is a remote execution vulnerability (CVE-2021-42392) in the latest version of gnite (2.16.0) using h2 (1.4.197)?
Contributor guide
Research direction
Start by reviewing the H2 dependency used by Ignite 2.16.0 and the reported CVE-2021-42392 details. Determine whether a supported H2 upgrade or documented mitigation is possible, then verify that the vulnerability is addressed without breaking Ignite compatibility.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- databases, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100