baidu / baidu/uid-generator

There is a vulnerability in logback 1.1.3,upgrade recommended

Open
#63 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
5.6k
Forks
1.5k
PR merge metrics
No merged PRs in 30d

Description

https://github.com/baidu/uid-generator/blob/2fcbc13d2016fcfb7648a18296951f6942215255/pom.xml#L71-L75

CVE-2017-5929

Recommended upgrade version:
1.1.11

Contributor guide

No contributing guide indexed for this repository

Research direction

Inspect pom.xml lines 71-75, where the logback dependency is declared, and review the reported CVE-2017-5929. Update the dependency to the recommended 1.1.11 version, then verify that the vulnerable 1.1.3 version is no longer referenced.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.