Skip to content

Conversation

@devinrsmith
Copy link
Member

https://nvd.nist.gov/vuln/detail/CVE-2022-3171
https://nvd.nist.gov/vuln/detail/CVE-2022-3509
https://nvd.nist.gov/vuln/detail/CVE-2022-3510

This might not be sufficient to take care of the CVEs above - it is probably more important to update the compilation protoc versions, which comes from protoc-base image, deephaven/deephaven-base-images#62

@devinrsmith devinrsmith added this to the June 2023 milestone Jun 15, 2023
@devinrsmith devinrsmith self-assigned this Jun 15, 2023
@devinrsmith devinrsmith marked this pull request as ready for review June 16, 2023 14:20
@devinrsmith
Copy link
Member Author

Actually, I think this is sufficient to fix the problem, as it seems to be the reflection-based API that is updated for CVEs mentioned above.

@devinrsmith devinrsmith requested a review from niloc132 June 16, 2023 15:06
@devinrsmith devinrsmith merged commit 2b2630a into deephaven:main Jun 16, 2023
@devinrsmith devinrsmith deleted the bump-protobuf-java branch June 16, 2023 20:26
@github-actions github-actions bot locked and limited conversation to collaborators Jun 16, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants