snowflakedb / snowflakedb/snowflake-ingest-java
Snyk: snowflake-ingest-java org.apache.commons:commons-compress 1.22 | Snyk ID - SNYK-JAVA-ORGAPACHECOMMONS-5901530
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 83
- Forks
- 70
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 6
Description
Title: Snyk: snowflake-ingest-java org.apache.commons:commons-compress 1.22
Additional information on Snyk can be found here: https://snyk.io/org/snowflakedb-sca-scanning-public-repo/project/34b0453e-1d9a-450b-9957-893ab6eaede1
Repo: snowflake-ingest-java
CVE: CVE-2023-42503
Package Type: java
Package Name: org.apache.commons:commons-compress
Package Version: 1.22
Snyk ID: SNYK-JAVA-ORGAPACHECOMMONS-5901530
Vulnerability URL: http://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-5901530
Severity: medium
Introduced Date: 2025-08-20
Projects with Vulnerability: snowflakedb/snowflake-ingest-java:e2e-jar-test/standard/pom.xml
Target File: e2e-jar-test/standard/pom.xml
JIRA Ticket: https://snowflakecomputing.atlassian.net/browse/SNOW-2280081
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with e2e-jar-test/standard/pom.xml and inspect the org.apache.commons:commons-compress 1.22 dependency. Review the CVE-2023-42503 details and the project's dependency checks, then update the dependency as appropriate. Done means the affected version is no longer present and the vulnerability check passes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 52/100