Skip to content

Update jaeger-client dependency due to CVE-2020-13949 #330

@lathspell

Description

@lathspell

You have an indirect dependency on libthrift:0.13.0 which has a security problem according to CVE-2020-13949.
Please update to opentracing-spring-jaeger-starter:3.3.3!

{noformat}
+--- io.opentracing.contrib:opentracing-spring-jaeger-cloud-starter:3.3.1
| +--- io.opentracing.contrib:opentracing-spring-jaeger-starter:3.3.1
| | --- io.jaegertracing:jaeger-client:1.3.2
| | +--- io.jaegertracing:jaeger-thrift:1.3.2
| | | +--- org.apache.thrift:libthrift:0.13.0
...
{noformat}

see also

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions