-
Notifications
You must be signed in to change notification settings - Fork 3.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[fix][sec] Upgrade Guava to 32.0.0 to address CVE-2023-2976 #20459
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@lhotari Can you attach a description of CVE-2023-2976? I don't find it on any advisory now.
Also, cross-post Guava 32.0.0 release note - https://github.com/google/guava/releases/tag/v32.0.0
It can introduce some imcompability changes while with a quick glance I don't think it would affect our usage.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
thanks. The CVE seems to be in the pipeline. There was a comment here: google/guava#2575 (comment)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
thanks. The CVE seems to be in the pipeline. There was a comment here: google/guava#2575 (comment)
It will be available at https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2976 when it has been published.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
similar as CVE-2020-8908
/pulsarbot rerun-failure-checks |
0513fd9
to
4345019
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you!
(cherry picked from commit 57f9467) # Conflicts: # pom.xml # pulsar-sql/presto-distribution/LICENSE
(cherry picked from commit 57f9467) # Conflicts: # distribution/server/src/assemble/LICENSE.bin.txt # pom.xml # pulsar-sql/presto-distribution/LICENSE
(cherry picked from commit 57f9467) # Conflicts: # pom.xml # pulsar-sql/presto-distribution/LICENSE
Motivation & Modifications
Upgrade Guava to 32.0.0 to address CVE-2023-2976
More details in Guava 32.0.0 release notes: https://github.com/google/guava/releases/tag/v32.0.0
Documentation
doc
doc-required
doc-not-needed
doc-complete