dockerzhang opened a new issue, #6867:
URL: https://github.com/apache/inlong/issues/6867

   ### Description
   
   https://github.com/dockerzhang/incubator-inlong/security/dependabot/95
   
   A parsing issue similar to 
https://github.com/advisories/GHSA-h4h5-3hr4-j3g2, but with textformat in 
protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 
can lead to a denial of service attack. Inputs containing multiple instances of 
non-repeated embedded messages with repeated or unknown fields causes objects 
to be converted back-n-forth between mutable and immutable forms, resulting in 
potentially long garbage collection pauses. We recommend updating to the 
versions mentioned above.
   
   ### InLong Component
   
   Other for not specified component
   
   ### Are you willing to submit PR?
   
   - [X] Yes, I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [X] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to