-
Notifications
You must be signed in to change notification settings - Fork 8.9k
security: fix some security vulnerabilities #5172
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
� Conflicts: � build/pom.xml
Codecov Report
@@ Coverage Diff @@
## develop #5172 +/- ##
=============================================
+ Coverage 48.87% 48.88% +0.01%
- Complexity 4169 4172 +3
=============================================
Files 743 743
Lines 26521 26521
Branches 3294 3294
=============================================
+ Hits 12963 12966 +3
+ Misses 12158 12152 -6
- Partials 1400 1403 +3
|
funky-eyes
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
wangliang181230
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
change.md加下。
done |
slievrly
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Ⅰ. Describe what this PR did
存在不少漏洞版本依赖,需要清除替换
https://mvnrepository.com/artifact/io.seata/seata-all/1.6.0
jackson-databind
版本:2.11.4>>2.13.4.1
CVE-2022-42004
CVE-2022-42003
protobuf-java
版本:3.11.4>>3.16.3
CVE-2022-3509
CVE-2022-3171
postgresql
版本:42.1.4>>42.3.3
CVE-2022-26520
CVE-2022-21724
spring-framework
版本:5.3.18>>5.3.20
CVE-2022-22971
nacos(暂未修改)
CVE-2021-43116
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43116
dubbo
版本:2.6.5>>2.6.10
CVE-2021-30179
CVE-2021-25640
guava
版本:27.0.1-jre>>30.1-jre
CVE-2020-8908
mysql-connector-java
版本:5.1.35>>5.1.42
CVE-2019-2692
CVE-2017-3589
CVE-2017-3523
Ⅱ. Does this pull request fix one issue?
fixes #5171
Ⅲ. Why don't you add test cases (unit test/integration test)?
Ⅳ. Describe how to verify it
Ⅴ. Special notes for reviews