-
Notifications
You must be signed in to change notification settings - Fork 3.7k
Closed
Labels
area/securitytype/bugThe PR fixed a bug or issue reported a bugThe PR fixed a bug or issue reported a bug
Milestone
Description
Issue
Black Duck, a product by Synopsys that scans for open source security threats, uncovered a few issues with dependencies for the Pulsar 2.3.1 binaries. Just posting the results here to make the community aware for future releases, I know this stuff is like a moving target.
Apache Commons Compress - 1.15
Apache Maven 2 - 3.0.4
AsyncHttpClient - 1.6.5
Guava: Google Core Libraries for Java - 21.0
Guava: Google Core Libraries for Java - 24.1-jre
jackson-databind - 2.8.11.3
- CVE-2018-1000873
- CVE-2018-14719
- CVE-2018-14720
- CVE-2018-14721
- CVE-2018-19360
- CVE-2018-19361
- CVE-2018-19362
Jetty: Java based HTTP, Servlet, SPDY, WebSocket Server - 9.4.11.v20180605
jQuery - 2.2.3
jQuery UI - 1.11.4
Netty Project - 3.10.1.Final
Netty Project - 3.6.2.Final
It looks like upgrading to the latest versions of each of these dependencies might patch things, but I am not certain.
Thanks!
Metadata
Metadata
Assignees
Labels
area/securitytype/bugThe PR fixed a bug or issue reported a bugThe PR fixed a bug or issue reported a bug