[
https://issues.apache.org/jira/browse/ORC-2035?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dongjoon Hyun resolved ORC-2035.
--------------------------------
Fix Version/s: 1.9.8
Resolution: Fixed
Issue resolved by pull request 2452
[https://github.com/apache/orc/pull/2452]
> Upgrade protobuf-java to 3.25.5 on branch-1.9
> ---------------------------------------------
>
> Key: ORC-2035
> URL: https://issues.apache.org/jira/browse/ORC-2035
> Project: ORC
> Issue Type: Improvement
> Affects Versions: 1.9.7
> Reporter: Manu Zhang
> Assignee: Manu Zhang
> Priority: Major
> Fix For: 1.9.8
>
>
> iceberg-spark-runtime depends on ORC 1.9.7 whose protobuf-java 3.22.3
> dependency has
> [CVE-2024-7254|https://github.com/advisories/GHSA-735f-pc8j-v9w8].
--
This message was sent by Atlassian Jira
(v8.20.10#820010)