apache / apache/incubator-seata

dependencies security vulnerability

Open
#5,720 0 comments 0 reactions 0 assignees View on GitHub
task: help-wanted
Dominant language
Java
Stars
26k
Forks
8.8k
Avg merge
1d 8h
Merged PRs (30d)
4

Description

- [ ] I have searched the [issues](https://github.com/seata/seata/issues) of this repository and believe that this is not a duplicate.

### Ⅰ. Issue Description

dependencies security vulnerability

![image](https://github.com/seata/seata/assets/8758457/752831a7-6a11-497e-bb1e-dcbcb1eee35a)
![image](https://github.com/seata/seata/assets/8758457/314625aa-79e2-4b07-bbab-d62054c0f63b)
![image](https://github.com/seata/seata/assets/8758457/4f6c7e13-d223-4b4e-b4da-ffecfa0447bb)
![image](https://github.com/seata/seata/assets/8758457/004df71f-482f-49dc-87c1-c2eb8084c1a3)
![image](https://github.com/seata/seata/assets/8758457/1999a401-b46e-48c4-968c-38a2a9263d1b)

### Ⅱ. Describe what happened

If there is an exception, please attach the exception trace:

```
Just paste your stack trace here!
```

### Ⅲ. Describe what you expected to happen

### Ⅳ. How to reproduce it (as minimally and precisely as possible)

1. xxx
2. xxx
3. xxx

Minimal yet complete reproducer code (or URL to code):

### Ⅴ. Anything else we need to know?

### Ⅵ. Environment:

- JDK version(e.g. `java -version`):
- Seata client/server version:
- Database version:
- OS(e.g. `uname -a`):
- Others:

Contributor guide

Open the contributing guide

Research direction

Start by reading the repository security policy linked in the issue and reviewing the attached vulnerability screenshots. Identify the affected dependencies and versions from that evidence, then confirm the required remediation and verify that the dependency vulnerability is resolved; the issue provides no file, test, or reproducer to start from.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
10/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.