Skip to content

Conversation

@burnerlee
Copy link

This PR bumps the version for software.amazon.awssdk » dynamodb from v2.32.0 to v2.32.33 to fix the vulnerabilities introduced due to its transitive dependencies.

Here is a log of vulnerabilities reporter when using dynamodb-streams-kinesis-adapter v2.0.1 by snyk:

  Upgrade software.amazon.awssdk:[email protected] to software.amazon.awssdk:[email protected] to fix
  ✗ Stack-based Buffer Overflow [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-10500754] in com.fasterxml.jackson.core:[email protected]
    introduced by software.amazon.awssdk:[email protected] > com.fasterxml.jackson.core:[email protected]
  ✗ Denial of Service (DoS) [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538] in com.fasterxml.jackson.core:[email protected]
    introduced by software.amazon.awssdk:[email protected] > com.fasterxml.jackson.core:[email protected]
  ✗ Allocation of Resources Without Limits or Throttling [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-IONETTY-11799531] in io.netty:[email protected]
    introduced by software.amazon.awssdk:[email protected] > io.netty:[email protected]
  ✗ Improper Handling of Highly Compressed Data (Data Amplification) [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-IONETTY-12485151] in io.netty:[email protected]
    introduced by software.amazon.awssdk:[email protected] > io.netty:[email protected]
  ✗ HTTP Request Smuggling [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-IONETTY-12485149] in io.netty:[email protected]
    introduced by software.amazon.awssdk:[email protected] > io.netty:[email protected]
  ✗ Improper Handling of Highly Compressed Data (Data Amplification) [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-IONETTY-12485150] in io.netty:[email protected]
    introduced by software.amazon.awssdk:[email protected] > io.netty:[email protected]
  ✗ Uncontrolled Recursion [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-10734078] in org.apache.commons:[email protected]
    introduced by software.amazon.awssdk:[email protected] > org.apache.commons:[email protected]

@burnerlee
Copy link
Author

@gguptp can we merge this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant