envoyproxy / envoyproxy/java-control-plane

Upgrade Protobuf Version to fix CVE-2024-7254

Open
#481 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
312
Forks
149
PR merge metrics
No merged PRs in 30d

Description

We are planning to use EnvoyRateLimiter in Apache Beam Java SDK. But there is a vulnerability with high severity. Can we upgrade the Protobuf version to resolve this. I can create a fix and raise PR

Design: https://s.apache.org/beam-api-ratelimiter

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.