xingwenpeng created HBASE-26234:
-----------------------------------
Summary: Protobuf-java-2.5.0.jar Has Several Security
Vulnerabilities,CVE-2015-5237,CVE-2019-15544
Key: HBASE-26234
URL: https://issues.apache.org/jira/browse/HBASE-26234
Project: HBase
Issue Type: Bug
Affects Versions: 2.2.3
Reporter: xingwenpeng
CVE-2019-15544:
Vulnerability Description:An issue was discovered in the protobuf crate before
2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.
CVE-2015-5237:
Vulnerability Description:protobuf allows remote authenticated attackers to
cause a heap-based buffer overflow.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)