Skip to content

[fix][sec] Upgrade Guava to 32.0.0 to address CVE-2023-2976#20459

Merged
lhotari merged 1 commit intoapache:masterfrom
lhotari:lh-address-CVE-2023-2976
Jun 1, 2023
Merged

[fix][sec] Upgrade Guava to 32.0.0 to address CVE-2023-2976#20459
lhotari merged 1 commit intoapache:masterfrom
lhotari:lh-address-CVE-2023-2976

Conversation

@lhotari
Copy link
Copy Markdown
Member

@lhotari lhotari commented Jun 1, 2023

Motivation & Modifications

Upgrade Guava to 32.0.0 to address CVE-2023-2976

More details in Guava 32.0.0 release notes: https://github.com/google/guava/releases/tag/v32.0.0

Documentation

  • doc
  • doc-required
  • doc-not-needed
  • doc-complete

@github-actions github-actions Bot added the doc-not-needed Your PR changes do not impact docs label Jun 1, 2023
@lhotari lhotari changed the title [fix][security] Upgrade Guava to 32.0.0 to address CVE-2023-2976 [fix][sec] Upgrade Guava to 32.0.0 to address CVE-2023-2976 Jun 1, 2023
Comment thread buildtools/pom.xml
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@lhotari Can you attach a description of CVE-2023-2976? I don't find it on any advisory now.

Also, cross-post Guava 32.0.0 release note - https://github.com/google/guava/releases/tag/v32.0.0

It can introduce some imcompability changes while with a quick glance I don't think it would affect our usage.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks. The CVE seems to be in the pipeline. There was a comment here: google/guava#2575 (comment)

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks. The CVE seems to be in the pipeline. There was a comment here: google/guava#2575 (comment)

It will be available at https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2976 when it has been published.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

similar as CVE-2020-8908

@lhotari
Copy link
Copy Markdown
Member Author

lhotari commented Jun 1, 2023

/pulsarbot rerun-failure-checks

Copy link
Copy Markdown
Member

@tisonkun tisonkun left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@lhotari lhotari merged commit 57f9467 into apache:master Jun 1, 2023
lhotari added a commit that referenced this pull request Jun 2, 2023
(cherry picked from commit 57f9467)

# Conflicts:
#	pom.xml
#	pulsar-sql/presto-distribution/LICENSE
lhotari added a commit that referenced this pull request Jun 6, 2023
(cherry picked from commit 57f9467)

# Conflicts:
#	distribution/server/src/assemble/LICENSE.bin.txt
#	pom.xml
#	pulsar-sql/presto-distribution/LICENSE
lhotari added a commit that referenced this pull request Jun 6, 2023
(cherry picked from commit 57f9467)

# Conflicts:
#	pom.xml
#	pulsar-sql/presto-distribution/LICENSE
nicoloboschi pushed a commit to datastax/pulsar that referenced this pull request Jun 6, 2023
…0459)

(cherry picked from commit 57f9467)

(cherry picked from commit 1cc99b3)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants