← All tasks
javaalibaba/Sentinel #1999Not a task: already works

There is a vulnerability in Spring Framework 5.1.9.RELEASE,upgrade recommended

envgap__alibaba__Sentinel-1999

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
dfce6ebba40509bb67515d8fc2b74e6255e411ef
Manifest
sentinel-adapter/sentinel-zuul2-adapter/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

alibaba/Sentinel #1999 · read the original issue
https://github.com/alibaba/Sentinel/blob/1f4614c0d4c5e966de1cd9f6715c8220937ef2a9/sentinel-adapter/sentinel-zuul2-adapter/pom.xml#L48



CVE-2020-5398 CVE-2020-5421





Recommended upgrade version:5.1.18.RELEASE
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]