Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

组件漏洞 #732

Closed
Tracked by #387 ...
gitYupan opened this issue Sep 25, 2023 · 4 comments · Fixed by #788
Closed
Tracked by #387 ...

组件漏洞 #732

gitYupan opened this issue Sep 25, 2023 · 4 comments · Fixed by #788
Labels
good first issue Good for newcomers

Comments

@gitYupan
Copy link

Describe the question or bug

以下组件有漏洞,被打包到sofa-ark-all-2.2.1.jar/lib/ 中,业务无法指定pom版本来进行升级
Guava-30.1-jre:CVE-2023-2976 -高危
Netty Handler-4.1.90.Final:CVE-2023-34462 -中危

Environment

  • SOFAArk version:2.2.1
  • JVM version (e.g. java -version):1.8
  • OS version (e.g. uname -a):Linux
@lvjing2
Copy link
Collaborator

lvjing2 commented Sep 25, 2023

你好,能详细解释下业务为何无法指定版本吗?

@gitYupan
Copy link
Author

上传到maven中央仓库的sofa-ark-all-2.2.1.jar将guava、netty等依赖打包到了sofa-ark-all-2.2.1.jar/lib/中
image

@gitYupan
Copy link
Author

报告图如下:
image

@lvjing2
Copy link
Collaborator

lvjing2 commented Sep 25, 2023

OK, 了解了,是 sofaArk compile 依赖了这几个依赖引入导致的。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants