Tencent / tinker

Tinker is a hot-fix solution library for Android, it supports dex, library and resources update without reinstall apk.
Other
17.16k stars 3.33k forks source link

There is a vulnerability in Guava: Google Core Libraries for Java 14.0.1,upgrade recommended #1524

Open QiAnXinCodeSafe opened 3 years ago

QiAnXinCodeSafe commented 3 years ago

https://github.com/Tencent/tinker/blob/b296864b8ec9f93e68537e6d44242af7ca3aa6ea/tinker-build/tinker-patch-lib/build.gradle#L13

CVE-2018-10237 CVE-2020-8908

Recommended upgrade version:24.1.1.jre