snowflakedb / snowflakedb/snowflake-ingest-java
Snyk: snowflake-ingest-java org.apache.commons:commons-compress 1.22 | Snyk ID - SNYK-JAVA-ORGAPACHECOMMONS-6254297
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 83
- Forks
- 70
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 6
Description
Title: Snyk: snowflake-ingest-java org.apache.commons:commons-compress 1.22
Additional information on Snyk can be found here: https://snyk.io/org/snowflakedb-sca-scanning-public-repo/project/34b0453e-1d9a-450b-9957-893ab6eaede1
Repo: snowflake-ingest-java
CVE: CVE-2024-26308
Package Type: java
Package Name: org.apache.commons:commons-compress
Package Version: 1.22
Snyk ID: SNYK-JAVA-ORGAPACHECOMMONS-6254297
Vulnerability URL: http://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-6254297
Severity: medium
Introduced Date: 2025-04-10
Projects with Vulnerability: snowflakedb/snowflake-ingest-java:e2e-jar-test/standard/pom.xml
Target File: e2e-jar-test/standard/pom.xml
JIRA Ticket: https://snowflakecomputing.atlassian.net/browse/SNOW-2036535
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Open e2e-jar-test/standard/pom.xml and review the org.apache.commons:commons-compress dependency in the context of CVE-2024-26308. Use the linked Snyk report for remediation guidance and check how this e2e JAR test is validated. Done means the dependency is updated to address the reported vulnerability and the relevant validation passes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100