[
https://issues.apache.org/jira/browse/FLINK-32371?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17734063#comment-17734063
]
Matthias Pohl edited comment on FLINK-32371 at 6/20/23 6:03 AM:
----------------------------------------------------------------
master: ba47237a0a44222a275ba7a1d144822466d20f15
1.17: 875c5900ed5ddaa187549c3bb62dd3bca679cfc5
1.16: 15061adddddb9eb049b679895c44454ca26b3186
was (Author: mapohl):
master: ba47237a0a44222a275ba7a1d144822466d20f15
1.17: tba
1.16: tba
> Bump snappy-java to 1.1.10.1
> ----------------------------
>
> Key: FLINK-32371
> URL: https://issues.apache.org/jira/browse/FLINK-32371
> Project: Flink
> Issue Type: Improvement
> Components: Build System
> Affects Versions: 1.16.2, 1.18.0, 1.17.1
> Reporter: Ryan Skraba
> Assignee: Ryan Skraba
> Priority: Major
> Labels: pull-request-available
> Fix For: 1.18.0
>
>
> There is a CVE in all versions of snappy prior to 1.1.10.1
> https://nvd.nist.gov/vuln/detail/CVE-2023-34455
--
This message was sent by Atlassian Jira
(v8.20.10#820010)