code4craft / webmagic

A scalable web crawler framework for Java.
http://webmagic.io/
Apache License 2.0
11.37k stars 4.18k forks source link

WebMagic Extension version 0.9.0 has CVE-2023-2976 vulnerability #1125

Open JackLinkai opened 1 year ago

JackLinkai commented 1 year ago

Brief description of bug

I have tried to use the latest version.On the maven repository, you can see that version 0.9.0 has CVE-2023-2976 vulnerability. This vulnerability comes from Guava, you can see on maven version 32.0.0 fixed this vulnerability, but it is not compatible with Windows system, I tried to use Guava 32.0.1-jre version, it can be used normally, and there are no dependency conflicts. image image