baidu / baidu/uid-generator

There is a vulnerability in spring 4.2.5.RELEASE,upgrade recommended

Open
#62 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
5.6k
Forks
1.5k
PR merge metrics
No merged PRs in 30d

Description

https://github.com/baidu/uid-generator/blob/2fcbc13d2016fcfb7648a18296951f6942215255/pom.xml#L18

CVE-2018-1270 CVE-2016-9878 CVE-2018-1272 CVE-2020-5421

Recommended upgrade version:4.3.28-1

Contributor guide

No contributing guide indexed for this repository

Research direction

Start at pom.xml line 18 and inspect the Spring dependency associated with the reported CVEs. Update it to the recommended 4.3.28-1 version, then run the project's existing build or tests to confirm the dependency resolves and passes.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.