Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

High Severity CVE in transitive dependency `jackson-core`

Đang mở
#1,198 3 bình luận 0 reaction 1 người được giao Xem trên GitHub

@lahirumaramba đang làm issue này rồi.

Từ ngày 27/5/2026.

Đánh giá

Issue này chưa được đánh giá.

Mô tả

api: core

firebase-admin-java 9.8.0 has a transitive dependency on com.fasterxml.jackson.core:jackson-core:2.18.2, which has https://osv.dev/vulnerability/GHSA-72hv-8253-57qq

here's the dependencyInsights output:

com.fasterxml.jackson.core:jackson-core:2.18.2 -> 2.18.6
--- com.google.cloud:google-cloud-storage:2.63.0
+--- runtimeClasspath (requested com.google.cloud:google-cloud-storage:{strictly 2.63.0})
+--- com.google.firebase:firebase-admin:9.8.0

(i couldnt find an open source repo for google-cloud-storage otherwise would have reported it there. Also tried to report through the security channel, but they said it wasnt severe enough to track as a security bug and to report on Github)

Ngôn ngữ chính
Java
Star
620
Fork
305
Merge trung bình
4 ngày 9 giờ
Pull request đã merge (30 ngày)
4

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của firebase/firebase-admin-java

Tất cả issue của firebase/firebase-admin-java

Issue tương tự

Thêm issue về Java

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.