Skip to content

Security Vulnerabilities - Black Duck Scan - Pulsar v.2.3.1 #4057

@one70six

Description

@one70six

Issue

Black Duck, a product by Synopsys that scans for open source security threats, uncovered a few issues with dependencies for the Pulsar 2.3.1 binaries. Just posting the results here to make the community aware for future releases, I know this stuff is like a moving target.

Apache Commons Compress - 1.15

Apache Maven 2 - 3.0.4

AsyncHttpClient - 1.6.5

Guava: Google Core Libraries for Java - 21.0

Guava: Google Core Libraries for Java - 24.1-jre

jackson-databind - 2.8.11.3

Jetty: Java based HTTP, Servlet, SPDY, WebSocket Server - 9.4.11.v20180605

jQuery - 2.2.3

jQuery UI - 1.11.4

Netty Project - 3.10.1.Final

Netty Project - 3.6.2.Final

It looks like upgrading to the latest versions of each of these dependencies might patch things, but I am not certain.

Thanks!

Metadata

Metadata

Assignees

Labels

area/securitytype/bugThe PR fixed a bug or issue reported a bug

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions