apache / apache/ignite

CVE-2024-38816 | Path Traversal Vulnerability found in Ignite 2.16.0 for spring boot

Open
#11,705 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
5.1k
Forks
1.9k
Avg merge
3d 2h
Merged PRs (30d)
46

Description

The spring-core version that the latest ignite uses is 5.2.25 which is vulnerable to Path Traversal (CVE-2024-38816). Is there any plan to upgrade this so that it uses latest spring framework?

Contributor guide

Open the contributing guide

Research direction

No file, test, or entry point is named. Start by locating the dependency declaration that selects spring-core 5.2.25 and review the supported Spring Framework version for Ignite 2.16.0. Done means the vulnerable dependency is upgraded to a non-vulnerable version and the relevant build or compatibility checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring, spring-boot
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.