There is a vulnerability in logback 1.1.3,upgrade recommended
Open
- Dominant language
- Java
- Stars
- 5.6k
- Forks
- 1.5k
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/baidu/uid-generator/blob/2fcbc13d2016fcfb7648a18296951f6942215255/pom.xml#L71-L75
CVE-2017-5929
Recommended upgrade version:
1.1.11
Contributor guide
No contributing guide indexed for this repository
Research direction
Inspect pom.xml lines 71-75, where the logback dependency is declared, and review the reported CVE-2017-5929. Update the dependency to the recommended 1.1.11 version, then verify that the vulnerable 1.1.3 version is no longer referenced.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 55/100