-
Notifications
You must be signed in to change notification settings - Fork 829
Dependency io.vertx:vertx-core, leading to CVE problem #705
Copy link
Copy link
Closed
Description
Hi, In client_java-parent/simpleclient_vertx,there is a dependency io.vertx:vertx-core:3.3.2 that calls the risk method.
The scope of this CVE affected version is [,3.5.2)
After further analysis, in this project, the main Api called is <io.vertx.core.http.impl.Http2HeadersAdaptor: io.vertx.core.MultiMap add(java.lang.String,java.lang.String)>
Risk method repair link : GitHub
CVE Bug Invocation Path--
Path Length : 3
<io.vertx.core.http.impl.Http2HeadersAdaptor: io.vertx.core.MultiMap add(java.lang.String,java.lang.String)>
at <io.vertx.core.http.impl.Http2ServerResponseImpl: io.vertx.core.http.HttpServerResponse putHeader(java.lang.String,java.lang.String)> (io.vertx.core.http.impl.Http2ServerResponseImpl.java:[211]) in /.m2/repository/io/vertx/vertx-core/3.3.2/vertx-core-3.3.2.jar
at <io.prometheus.client.vertx.MetricsHandler: void handle(io.vertx.ext.web.RoutingContext)> (io.prometheus.client.vertx.MetricsHandler.java:[81]) in /detect/unzip/client_java-parent-0.11.0/simpleclient_vertx/target/classes
Dependency tree--
[INFO] io.prometheus:simpleclient_vertx:bundle:0.11.0
[INFO] +- io.prometheus:simpleclient:jar:0.11.0:compile
[INFO] | +- io.prometheus:simpleclient_tracer_otel:jar:0.11.0:compile
[INFO] | | \- io.prometheus:simpleclient_tracer_common:jar:0.11.0:compile
[INFO] | \- io.prometheus:simpleclient_tracer_otel_agent:jar:0.11.0:compile
[INFO] +- io.prometheus:simpleclient_common:jar:0.11.0:compile
[INFO] +- io.vertx:vertx-web:jar:3.3.2:provided
[INFO] | +- io.vertx:vertx-auth-common:jar:3.3.2:provided
[INFO] | \- io.vertx:vertx-core:jar:3.3.2:provided
[INFO] | +- io.netty:netty-common:jar:4.1.1.Final:provided
[INFO] | +- io.netty:netty-buffer:jar:4.1.1.Final:provided
[INFO] | +- io.netty:netty-transport:jar:4.1.1.Final:provided
[INFO] | +- io.netty:netty-handler:jar:4.1.1.Final:provided
[INFO] | | \- io.netty:netty-codec:jar:4.1.1.Final:provided
[INFO] | +- io.netty:netty-handler-proxy:jar:4.1.1.Final:provided
[INFO] | | \- io.netty:netty-codec-socks:jar:4.1.1.Final:provided
[INFO] | +- io.netty:netty-codec-http:jar:4.1.1.Final:provided
[INFO] | +- io.netty:netty-codec-http2:jar:4.1.1.Final:provided
[INFO] | +- io.netty:netty-resolver:jar:4.1.1.Final:provided
[INFO] | +- io.netty:netty-resolver-dns:jar:4.1.1.Final:provided
[INFO] | | \- io.netty:netty-codec-dns:jar:4.1.1.Final:provided
[INFO] | +- com.fasterxml.jackson.core:jackson-core:jar:2.7.4:provided
[INFO] | \- com.fasterxml.jackson.core:jackson-databind:jar:2.7.4:provided
[INFO] | \- com.fasterxml.jackson.core:jackson-annotations:jar:2.7.0:provided
Suggested solutions:
Update dependency version
Thank you very much.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels