google / google/bundletool

The latest version of the `BundleTool` library (1.18.0) is still vulnerable to the `CVE-2024-7254` security vulnerability

Open
#382 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
4k
Forks
428
PR merge metrics
No merged PRs in 30d

Description

The latest version of the `BundleTool` library (1.18.0) is still vulnerable to the CVE-2024-7254 security vulnerability. This vulnerability comes from the `protobuf-java` dependency and has affected the `BundleTool` library for several years.

Many organizations enforce strict policies against using binaries with known security vulnerabilities. Please consider updating the `protobuf-java` dependency used by the `BundleTool` library from version `3.22.3` to at least `3.25.5` to address this issue.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.