envoyproxy / envoyproxy/java-control-plane
Upgrade Protobuf Version to fix CVE-2024-7254
Open
- Dominant language
- Java
- Stars
- 312
- Forks
- 149
- PR merge metrics
- No merged PRs in 30d
Description
We are planning to use EnvoyRateLimiter in Apache Beam Java SDK. But there is a vulnerability with high severity. Can we upgrade the Protobuf version to resolve this. I can create a fix and raise PR
Design: https://s.apache.org/beam-api-ratelimiter
Contributor guide
Assessment
This issue has not been assessed yet.