Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Current version of MessagePack has vulnerability. #867

Closed
VladimirRudt opened this issue Nov 2, 2024 · 1 comment
Closed

Current version of MessagePack has vulnerability. #867

VladimirRudt opened this issue Nov 2, 2024 · 1 comment

Comments

@VladimirRudt
Copy link

Hi guys, We are using MagicOnion in one of our projects and we encountered a problem.

The Mend.io diagnostic service has detected that we are using a vulnerable version of MessagePack. We don't use MessagePack directly, but MagicOnion (v6.1.5) does:

image

Link to vulnerability description: GHSA-4qm4-8hg2-g2xm

Do you plan to upgrade MessagePack to the patched version 2.5.187?

mayuki added a commit that referenced this issue Nov 5, 2024
@mayuki
Copy link
Member

mayuki commented Nov 6, 2024

Thank you for your feedback. We have released 6.1.6, which includes an update to MessagePack.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants