snowflakedb / snowflakedb/snowflake-ingest-java
Snyk: snowflake-ingest-java org.apache.avro:avro 1.11.3 | Snyk ID - SNYK-JAVA-ORGAPACHEAVRO-8161188
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 83
- Forks
- 70
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 6
Description
Title: Snyk: snowflake-ingest-java org.apache.avro:avro 1.11.3
Additional information on Snyk can be found here: https://snyk.io/org/snowflakedb-sca-scanning-public-repo/project/34b0453e-1d9a-450b-9957-893ab6eaede1
Repo: snowflake-ingest-java
CVE: CVE-2024-47561
Package Type: java
Package Name: org.apache.avro:avro
Package Version: 1.11.3
Snyk ID: SNYK-JAVA-ORGAPACHEAVRO-8161188
Vulnerability URL: http://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHEAVRO-8161188
Severity: critical
Introduced Date: 2025-04-10
Projects with Vulnerability: snowflakedb/snowflake-ingest-java:e2e-jar-test/standard/pom.xml
Target File: e2e-jar-test/standard/pom.xml
JIRA Ticket: https://snowflakecomputing.atlassian.net/browse/SNOW-2043257
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with e2e-jar-test/standard/pom.xml, the target file named in the issue, and review the Snyk advisory for CVE-2024-47561. Identify the supported non-vulnerable org.apache.avro:avro version and update the dependency there. Done means the critical vulnerability is resolved for the standard e2e JAR test project and its build still passes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100