mrmadira opened a new issue, #7530:
URL: https://github.com/apache/iceberg/issues/7530

   protobuf CVEs reported on iceberg-spark-runtime jar
   
   CVE | Severity | Package | Package Path
   -- | -- | -- | --
   CVE-2022-3171 | high | protobuf-java | 
iceberg-spark-runtime-3.3_2.12-1.1.0.jar
   CVE-2022-3509 | high | protobuf-java | 
iceberg-spark-runtime-3.3_2.12-1.1.0.jar
   CVE-2022-3510 | high | protobuf-java | 
iceberg-spark-runtime-3.3_2.12-1.1.0.jar
   
   These are very old CVEs. Can someone please advise if the CVEs are 
applicable and is there a plan to bump up the version?
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to