Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug report] Guava 31.1-jre has two security issues, one is high #1755

Closed
justinmclean opened this issue Jan 29, 2024 · 0 comments · Fixed by #1807
Closed

[Bug report] Guava 31.1-jre has two security issues, one is high #1755

justinmclean opened this issue Jan 29, 2024 · 0 comments · Fixed by #1807
Assignees
Labels
bug Something isn't working

Comments

@justinmclean
Copy link
Member

Version

main branch

Describe what's wrong

CVE-2023-2976 (NVD) is high severity and is fixed in 32.0.1. See https://nvd.nist.gov/vuln/detail/CVE-2023-2976 for more info. CVE-2020-8908 is of low severity. A sreach of our code shows we are unlikely to be impaced by this.

Error message and/or stacktrace

N/A

How to reproduce

See CVE details and libs.version.toml where guava = "31.1-jre" is used.

Additional context

No response

@justinmclean justinmclean added the bug Something isn't working label Jan 29, 2024
@jerryshao jerryshao added this to the Gravitino 0.4.0 milestone Jan 31, 2024
jerryshao pushed a commit that referenced this issue Jan 31, 2024
### What changes were proposed in this pull request?
update guava from 31.1-jre to 32.1.3-jre

### Why are the changes needed?

Fix: #1755 

### Does this PR introduce _any_ user-facing change?
no

### How was this patch tested?
existing tests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants