[
https://issues.apache.org/jira/browse/SPARK-39738?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17641479#comment-17641479
]
Eugene Shinn (Truveta) commented on SPARK-39738:
------------------------------------------------
[email protected] has upgraded to a non-vulnerable version of protobuf so we should be
able to upgrade now to get rid of this vulernability.
> ORC uses Protobuf version vulnerable to CVE-2021-22569
> ------------------------------------------------------
>
> Key: SPARK-39738
> URL: https://issues.apache.org/jira/browse/SPARK-39738
> Project: Spark
> Issue Type: Bug
> Components: Spark Core
> Affects Versions: 3.2.1, 3.3.0
> Reporter: Eugene Shinn (Truveta)
> Priority: Major
>
> Our static analysis software detected vulnerability
> [CVE-2021-22569|https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-wrvw-hg22-4m67],
> which comes from [ORC-1212] [email protected] has CVE-2021-22569 - ASF
> JIRA (apache.org).
> Once ORC has addressed this vulnerability, Spark should upgrade to the next
> non-vulnerable version.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]