CVE-2024-38816 | Path Traversal Vulnerability found in Ignite 2.16.0 for spring boot
Open
- Dominant language
- Java
- Stars
- 5.1k
- Forks
- 1.9k
- Avg merge
- 3d 2h
- Merged PRs (30d)
- 46
Description
The spring-core version that the latest ignite uses is 5.2.25 which is vulnerable to Path Traversal (CVE-2024-38816). Is there any plan to upgrade this so that it uses latest spring framework?
Contributor guide
Research direction
No file, test, or entry point is named. Start by locating the dependency declaration that selects spring-core 5.2.25 and review the supported Spring Framework version for Ignite 2.16.0. Done means the vulnerable dependency is upgraded to a non-vulnerable version and the relevant build or compatibility checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring, spring-boot
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100