apache / apache/pulsar-manager
There is a vulnerability in Spring Boot 2.0.2.RELEASE,upgrade recommended
Open
- Dominant language
- Vue
- Stars
- 539
- Forks
- 239
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/apache/pulsar-manager/blob/d15a0f1e45a3fe9821df51361584dce87e104948/build.gradle#L17
CVE-2020-5421
Recommended upgrade version:
2.1.17.RELEASE
Contributor guide
Research direction
Open build.gradle at line 17 and inspect the Spring Boot 2.0.2.RELEASE dependency associated with CVE-2020-5421. Update it to the recommended 2.1.17.RELEASE version, then verify that the resolved dependency uses that version and no longer matches the reported vulnerable release.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- spring-boot
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100