apache / apache/beam

There is a vulnerability in Protocol Buffers 0.8.13,upgrade recommended

Open
#22,886 0 comments 0 reactions 0 assignees View on GitHub
build P2
Dominant language
Java
Stars
8.7k
Forks
4.7k
Avg merge
2d 2h
Merged PRs (30d)
205

Description

https://github.com/apache/beam/blob/42b1640a25d5dbdea08ae2feaa0d3e81f6278575/buildSrc/build.gradle.kts#L42

CVE-2021-22570

Recommended upgrade version:0.8.19

Contributor guide

Open the contributing guide

Research direction

Start at buildSrc/build.gradle.kts line 42, where Protocol Buffers 0.8.13 is declared, and review CVE-2021-22570. Update the dependency to the recommended 0.8.19 version, then run the relevant build or dependency checks to confirm the vulnerability is addressed.

Written by the indexing model from the issue text.

Assessment

Tech stack
kotlin
Domain
build-system, security
Issue type
Bug
Difficulty
1/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.