Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade protobuf to 3.25.5 to address CVE-2024-7254 #4508

Merged
merged 1 commit into from
Sep 25, 2024

Conversation

lhotari
Copy link
Member

@lhotari lhotari commented Sep 23, 2024

Motivation

CVE-2024-7254

Changes

Upgrade protobuf to 3.25.5

@lhotari lhotari added this to the 4.18.0 milestone Sep 23, 2024
@lhotari lhotari self-assigned this Sep 23, 2024
@lhotari
Copy link
Member Author

lhotari commented Sep 23, 2024

Upgrading in Pulsar isn't simple. Related Pulsar dev mailing list message: https://lists.apache.org/thread/73jk2mx4nj82kxwvwgcqz5m63scqcy2s

@lhotari
Copy link
Member Author

lhotari commented Sep 23, 2024

We should also upgrade grpc to latest stable which is compatible with 3.25.5 when we upgrade branch-4.17 and branch-4.16.

@hezhangjian hezhangjian merged commit 0229b5d into apache:master Sep 25, 2024
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants