There is a vulnerability in snakeyaml 1.23,upgrade recommended
Open
- Dominant language
- Java
- Stars
- 47
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/didi/benchmark-thrift/blob/e6a6caf235f4ef81d3b1ccb20b812840f27a9c44/pom.xml#L19-L21
CVE-2017-18640
Recommended upgrade version:1.26
Contributor guide
Research direction
Open pom.xml at lines 19–21 and inspect the SnakeYAML 1.23 dependency. Read the details of CVE-2017-18640, update the dependency to the recommended 1.26 version, and verify that the project still builds successfully.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100