googleads / googleads/googleads-java-lib

Apache Axis Should Be Replaced by Axis 2 Due to Multiple CVEs and EOL

Open
#268 2 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement P2
Dominant language
Java
Stars
234
Forks
360
PR merge metrics
No merged PRs in 30d

Description

This is kind of a re-opening of issue #240 from last year where a high CVE was opened against Axis 1 library CVE-2019-0227. A new critical CVE has been opened against the Axis 1 library: CVE-2023-40743. I had attempted to follow the advice given in #240 and use the dfp-appengine, but found too many breaking changes in using it that I'm forced to continue leveraging dfp-axis. Even the latest 5.2.0 release continues to utilize Axis 1.4. Can you please consider upgrading to Axis 2?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing issue #240 and comparing the dfp-axis and dfp-appengine approaches described in the issue. Investigate the current Axis 1.4 dependency in the 5.2.0 release and the compatibility impact of moving to Axis 2; done means the library no longer relies on Axis 1 while preserving required API behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, security
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.