apache / apache/mina-ftpserver
Request for Update on Vulnerability Fix and Upgrade Timeline for "org.apache.mina:mina-core@2.0.4"
- Dominant language
- Java
- Stars
- 67
- Forks
- 38
- PR merge metrics
- No merged PRs in 30d
Description
Hi Team,
We have identified a vulnerability in our organization originating from the library org.apache.mina:mina-core@2.0.4. This library is a dependency of org.apache.ftpserver:ftpserver-core@1.0.6.
To address the issue, we attempted to update the FTP server version to 1.2.0. However, the vulnerability persists even with this version. According to the details, the fix requires upgrading mina-core to one of the following versions:
org.apache.mina:mina-core@2.0.27
org.apache.mina:mina-core@2.1.10
org.apache.mina:mina-core@2.2.4
Could you please let us know when the next upgrade is expected to address this issue? Any updates or guidance regarding this matter would be greatly appreciated.
Looking forward to your response.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the reported vulnerability and the current dependency versions for org.apache.ftpserver:ftpserver-core and org.apache.mina:mina-core. Confirm which Mina version resolves the vulnerability and determine the upgrade timeline or compatibility constraints; done requires documented guidance or an upgrade that removes the vulnerable dependency.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- networking, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100