[
https://issues.apache.org/jira/browse/HBASE-26234?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17406166#comment-17406166
]
xingwenpeng commented on HBASE-26234:
-------------------------------------
If the version is upgraded to 3.15.8, compatibility issues may occur.
> Protobuf-java-2.5.0.jar Has Several Security
> Vulnerabilities,CVE-2015-5237,CVE-2019-15544
> -----------------------------------------------------------------------------------------
>
> Key: HBASE-26234
> URL: https://issues.apache.org/jira/browse/HBASE-26234
> Project: HBase
> Issue Type: Bug
> Affects Versions: 2.2.3
> Reporter: xingwenpeng
> Priority: Major
>
> CVE-2019-15544:
> Vulnerability Description:An issue was discovered in the protobuf crate
> before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve
> calls.
> CVE-2015-5237:
> Vulnerability Description:protobuf allows remote authenticated attackers to
> cause a heap-based buffer overflow.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)