[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2024-02-27 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17821186#comment-17821186 ] PJ Fanning commented on HADOOP-18197: - I have https://github.com/apache/hadoop-thirdparty/pull/34

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2024-02-27 Thread Steve Loughran (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17821183#comment-17821183 ] Steve Loughran commented on HADOOP-18197: - +1 for moving to 3.23; trying to maintain someone

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2024-02-26 Thread Ayush Saxena (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17820711#comment-17820711 ] Ayush Saxena commented on HADOOP-18197: --- If protobuf 3.23 has a fix & released, I think we should

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2024-02-26 Thread PJ Fanning (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17820707#comment-17820707 ] PJ Fanning commented on HADOOP-18197: - The fix only seems to be in protobuf-java 3.23 and above -

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2024-02-21 Thread Steve Loughran (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17819229#comment-17819229 ] Steve Loughran commented on HADOOP-18197: - saw this in the context of surefire upgrade #6537.

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2024-02-19 Thread Ayush Saxena (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17818651#comment-17818651 ] Ayush Saxena commented on HADOOP-18197: --- I think this is causing some trouble due to some

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-08-21 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17756952#comment-17756952 ] ASF GitHub Bot commented on HADOOP-18197: - steveloughran commented on PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-08-18 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17756029#comment-17756029 ] ASF GitHub Bot commented on HADOOP-18197: - janjwerner-confluent commented on PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-07-10 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17741520#comment-17741520 ] ASF GitHub Bot commented on HADOOP-18197: - steveloughran commented on PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-07-10 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17741475#comment-17741475 ] ASF GitHub Bot commented on HADOOP-18197: - abhishekagarwal87 commented on PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-03-30 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17706870#comment-17706870 ] ASF GitHub Bot commented on HADOOP-18197: - steveloughran commented on PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-03-30 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17706867#comment-17706867 ] ASF GitHub Bot commented on HADOOP-18197: - steveloughran commented on code in PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-03-30 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17706779#comment-17706779 ] ASF GitHub Bot commented on HADOOP-18197: - xizhu-mstr commented on code in PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-03-30 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17706777#comment-17706777 ] ASF GitHub Bot commented on HADOOP-18197: - xizhu-mstr commented on code in PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-02-27 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17694332#comment-17694332 ] ASF GitHub Bot commented on HADOOP-18197: - tooptoop4 commented on code in PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2023-02-27 Thread t oo (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17694304#comment-17694304 ] t oo commented on HADOOP-18197: --- CVE-2022-3510 and CVE-2022-3509  h1.  > Update protobuf 3.7.1 to a

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2022-10-24 Thread t oo (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17623569#comment-17623569 ] t oo commented on HADOOP-18197: --- CVE-2022-3171 > Update protobuf 3.7.1 to a version without

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2022-10-20 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17621198#comment-17621198 ] ASF GitHub Bot commented on HADOOP-18197: - hadoop-yetus commented on PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2022-10-10 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17615238#comment-17615238 ] ASF GitHub Bot commented on HADOOP-18197: - hadoop-yetus commented on PR #4418: URL:

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2022-10-10 Thread Steve Loughran (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17615157#comment-17615157 ] Steve Loughran commented on HADOOP-18197: - I'm doing a version of thirdparty jar where the

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2022-08-09 Thread Steve Loughran (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17577362#comment-17577362 ] Steve Loughran commented on HADOOP-18197: - that unshaded protobuf 2.5 has primarily been there

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2022-08-09 Thread Steve Loughran (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17577359#comment-17577359 ] Steve Loughran commented on HADOOP-18197: - bq. Just out of curiosity: what's the plan for

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2022-08-09 Thread Tamas Domok (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17577223#comment-17577223 ] Tamas Domok commented on HADOOP-18197: -- Hi [~ste...@apache.org], Based on

[jira] [Commented] (HADOOP-18197) Update protobuf 3.7.1 to a version without CVE-2021-22569

2022-04-11 Thread Steve Loughran (Jira)
[ https://issues.apache.org/jira/browse/HADOOP-18197?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17520557#comment-17520557 ] Steve Loughran commented on HADOOP-18197: - [~ivan.viaznikov] HADOOP-16557 upgraded our internal