Skip to content

0.8.1

Latest
Compare
Choose a tag to compare
@eed3si9n eed3si9n released this 20 Oct 15:44
· 2 commits to main since this release
v0.8.1
6ee5096

Protobuf with potential Denial of Service (CVE-2024-7254)

sbt-protobuf 0.8.1 updates protobuf-java library to 3.25.5 to address CVE-2024-7254 / GHSA-735f-pc8j-v9w8, which states that while parsing unknown fields in the Protobuf Java library, a maliciously crafted message can cause a StackOverflow error.

behind the scene

Full Changelog: v0.8.0...v0.8.1