Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address CVE-2024-7254 vulnerability in the standard libraries #7013

Open
4 tasks done
TharmiganK opened this issue Sep 20, 2024 · 0 comments
Open
4 tasks done

Address CVE-2024-7254 vulnerability in the standard libraries #7013

TharmiganK opened this issue Sep 20, 2024 · 0 comments
Assignees
Labels
Team/PCM Protocol connector packages related issues Type/Task

Comments

@TharmiganK
Copy link
Contributor

TharmiganK commented Sep 20, 2024

Description:

The following security vulnerability is detected with protobuf-java library:

Library Vulnerability Severity Status Installed Version Fixed Version Title
com.google.protobuf:protobuf-java (protobuf-java-3.20.3.jar) CVE-2024-7254 HIGH fixed 3.20.3 3.25.5, 4.27.5, 4.28.2 protobuf-java has potential Denial of Service issue

Describe your task(s)

Need to update the version to 3.25.5 in the following standard libraries

  • protobuf
  • tcp
  • http
  • grpc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team/PCM Protocol connector packages related issues Type/Task
Projects
None yet
Development

No branches or pull requests

3 participants