[
https://issues.apache.org/jira/browse/FLINK-32371?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Matthias Pohl resolved FLINK-32371.
-----------------------------------
Fix Version/s: 1.16.3
1.17.2
Resolution: Fixed
> Bump snappy-java to 1.1.10.1
> ----------------------------
>
> Key: FLINK-32371
> URL: https://issues.apache.org/jira/browse/FLINK-32371
> Project: Flink
> Issue Type: Improvement
> Components: Build System
> Affects Versions: 1.16.2, 1.18.0, 1.17.1
> Reporter: Ryan Skraba
> Assignee: Ryan Skraba
> Priority: Major
> Labels: pull-request-available
> Fix For: 1.18.0, 1.16.3, 1.17.2
>
>
> There is a CVE in all versions of snappy prior to 1.1.10.1
> https://nvd.nist.gov/vuln/detail/CVE-2023-34455
--
This message was sent by Atlassian Jira
(v8.20.10#820010)