eclipse-paho / eclipse-paho/paho.mqtt.java
Unmaintained eclipse release
- Dominant language
- Java
- Stars
- 2.3k
- Forks
- 919
- PR merge metrics
- No merged PRs in 30d
Description
Please fill out the form below before submitting, thank you!
- [x ] Bug exists Release Version 1.2.0 ( Master Branch)
- [x ] Bug exists in MQTTv3 Client on Snapshot Version 1.2.1-SNAPSHOT (Develop Branch)
- [x] Bug exists in MQTTv5 Client on Snapshot Version 1.2.1-SNAPSHOT (Develop Branch)
If this is a bug regarding the Android Service, please raise the bug here instead: https://github.com/eclipse/paho.mqtt.android/issues/new
The original Bug is that paho 1.2.0 uses nsecure components with CVE present (i.e. batik).
Even the develop branch uses an AFAIK now unmaintanted eclipse release.
Suggest an update. Pull request to follow.
Contributor guide
Research direction
No file, test, or entry point is named. Start by locating the dependency declarations for the affected Eclipse component and checking the vulnerable batik version and CVE details. Done means updating to a maintained, non-vulnerable release and confirming the project’s existing build and tests pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100