golang / golang/appengine

CVE-2024-24786

Open
#349 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
Go
Stars
671
Forks
203
PR merge metrics
No merged PRs in 30d

Description

There is a security issue with google.golang.org/protobuf:

https://nvd.nist.gov/vuln/detail/CVE-2024-24786

It was fixed with this commit:
https://github.com/protocolbuffers/protobuf-go/commit/f01a588e5810b90996452eec4a28f22a0afae023

So, google.golang.org/protobuf should be upgraded to 1.33.0.
Also, github.com/golang/protobuf version 1.5.4 uses the fixed version of google.golang.org/protobuf. That should be upgraded too.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.