Skip to content

[Java] Apache Arrow — Stack overflow in Protocol Buffers Java Lite — CVE-2024-7254 #44770

Description

@hvub

Describe the enhancement requested

Regarding Apache Arrow dependency to com.google.protobuf:protobuf-java-util
https://github.com/apache/arrow/blob/main/java/pom.xml#L101

Please consider updating the dependency to 3.25.5 to address CVE-2024-7254

cf.
https://www.cve.org/CVERecord?id=CVE-2024-7254
https://vulert.com/vuln-db/CVE-2024-7254
https://ogma.in/understanding-cve-2024-7254-vulnerability-in-protocol-buffers-and-mitigation-strategies

Component(s)

Java

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions