snowflakedb / snowflakedb/snowflake-ingest-java
Snyk: snowflake-ingest-java com.nimbusds:nimbus-jose-jwt 9.48 | Snyk ID - SNYK-JAVA-COMNIMBUSDS-10691768
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 83
- Forks
- 70
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 6
Description
Title: Snyk: snowflake-ingest-java com.nimbusds:nimbus-jose-jwt 9.48
Additional information on Snyk can be found here: https://snyk.io/org/snowflakedb-sca-scanning-public-repo/project/0a0b0a8c-113f-4e60-98d3-357b27f5338d
Repo: snowflake-ingest-java
CVE: CVE-2025-53864
Package Type: java
Package Name: com.nimbusds:nimbus-jose-jwt
Package Version: 9.48
Snyk ID: SNYK-JAVA-COMNIMBUSDS-10691768
Vulnerability URL: http://security.snyk.io/vuln/SNYK-JAVA-COMNIMBUSDS-10691768
Severity: medium
Introduced Date: 2025-07-11
Projects with Vulnerability: snowflakedb/snowflake-ingest-java:e2e-jar-test/core/pom.xml
Target File: e2e-jar-test/core/pom.xml
JIRA Ticket: https://snowflakecomputing.atlassian.net/browse/SNOW-2201967
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with e2e-jar-test/core/pom.xml and inspect the com.nimbusds:nimbus-jose-jwt dependency at version 9.48. Review the CVE-2025-53864 details and the Snyk vulnerability record to determine the supported remediation, then verify that the dependency is no longer reported as vulnerable.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100