There is a vulnerability in spring 4.2.5.RELEASE,upgrade recommended
Open
- Dominant language
- Java
- Stars
- 5.6k
- Forks
- 1.5k
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/baidu/uid-generator/blob/2fcbc13d2016fcfb7648a18296951f6942215255/pom.xml#L18
CVE-2018-1270 CVE-2016-9878 CVE-2018-1272 CVE-2020-5421
Recommended upgrade version:4.3.28-1
Contributor guide
No contributing guide indexed for this repository
Research direction
Start at pom.xml line 18 and inspect the Spring dependency associated with the reported CVEs. Update it to the recommended 4.3.28-1 version, then run the project's existing build or tests to confirm the dependency resolves and passes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- security
- Issue type
- Bug
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 30/100