vipshop / Saturn

The vip.com's distributed job scheduling platform.
Apache License 2.0
2.27k stars 698 forks source link

There is a vulnerability in guava 18.0 ,upgrade recommended #726

Open QiAnXinCodeSafe opened 3 years ago

QiAnXinCodeSafe commented 3 years ago

https://github.com/vipshop/Saturn/blob/032796b7036d53f09a75de0a13808e48dce210f7/pom.xml#L60

CVE-2018-10237

Recommended upgrade version:24.1.1.jre