firebase / firebase/firebase-admin-java

High Severity CVE in transitive dependency `jackson-core`

未關閉
#1,198 3 則留言 0 個 reaction 已指派 1 人 已被 @lahirumaramba 認領 在 GitHub 檢視
api: core
主要語言
Java
星號
620
分支
305
平均合併
3 小時 23 分鐘
30 天內合併 PR
1

描述

firebase-admin-java 9.8.0 has a transitive dependency on com.fasterxml.jackson.core:jackson-core:2.18.2, which has https://osv.dev/vulnerability/GHSA-72hv-8253-57qq

here's the dependencyInsights output:

com.fasterxml.jackson.core:jackson-core:2.18.2 -> 2.18.6
\--- com.google.cloud:google-cloud-storage:2.63.0
+--- runtimeClasspath (requested com.google.cloud:google-cloud-storage:{strictly 2.63.0})
+--- com.google.firebase:firebase-admin:9.8.0

(i couldnt find an open source repo for google-cloud-storage otherwise would have reported it there. Also tried to report through the security channel, but they said it wasnt severe enough to track as a security bug and to report on Github)

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。