Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

jasypt version 1.9.3 is vulnerable to CVE-2022-22965

Open
#1,997 9 comments 0 reactions 1 assignee View on GitHub

@jbonofre is already working on this.

Since May 7, 2026.

Assessment

This issue has not been assessed yet.

Description

Can this dependency be updated? Its vulnerable to a a number of old CVEs some of which are rated high.

Dominant language
Java
Stars
2.5k
Forks
1.5k
Avg merge
9h 25m
Merged PRs (30d)
81

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/activemq

All issues in apache/activemq

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.