eclipse-paho / eclipse-paho/paho.mqtt.java

Unmaintained eclipse release

Open
#543 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
2.3k
Forks
919
PR merge metrics
No merged PRs in 30d

Description

Please fill out the form below before submitting, thank you!

- [x ] Bug exists Release Version 1.2.0 ( Master Branch)
- [x ] Bug exists in MQTTv3 Client on Snapshot Version 1.2.1-SNAPSHOT (Develop Branch)
- [x] Bug exists in MQTTv5 Client on Snapshot Version 1.2.1-SNAPSHOT (Develop Branch)

If this is a bug regarding the Android Service, please raise the bug here instead: https://github.com/eclipse/paho.mqtt.android/issues/new

The original Bug is that paho 1.2.0 uses nsecure components with CVE present (i.e. batik).

Even the develop branch uses an AFAIK now unmaintanted eclipse release.

Suggest an update. Pull request to follow.

Contributor guide

Open the contributing guide

Research direction

No file, test, or entry point is named. Start by locating the dependency declarations for the affected Eclipse component and checking the vulnerable batik version and CVE details. Done means updating to a maintained, non-vulnerable release and confirming the project’s existing build and tests pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.