apache / apache/rocketmq-exporter

Security - 0.0.2 version has high vulnerabilities of CVE-2022-25845, CVE-2023-34981, and GHSA-xpw8-rcwv-8f8p

Open
#181 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
324
Forks
178
PR merge metrics
No merged PRs in 30d

Description

**Describe the bug**
Security - 0.0.2 version has high vulnerabilities of CVE-2022-25845, CVE-2023-34981, and GHSA-xpw8-rcwv-8f8p.

**To Reproduce**
1. CVE-2022-25845: com.alibaba:fastjson, see https://github.com/advisories/GHSA-pv7h-hx5h-mgfj.
2. CVE-2023-34981: org.apache.tomcat.embed:tomcat-embed-core, see https://github.com/advisories/GHSA-mppv-79ch-vw6q.
3. GHSA-xpw8-rcwv-8f8p: io.netty:netty-codec-http2, see https://github.com/advisories/GHSA-xpw8-rcwv-8f8p.

**Expected behavior**
They should be fixed.

**Screenshots**
n/a

**Desktop (please complete the following information):**
n/a

**Smartphone (please complete the following information):**
n/a

**Additional context**
n/a

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.