ballerina-platform / ballerina-library

The Ballerina Library
https://ballerina.io/learn/api-docs/ballerina/
Apache License 2.0
137 stars 58 forks source link

Address `CVE-2024-7254` vulnerability in the standard libraries #7013

Open TharmiganK opened 1 week ago

TharmiganK commented 1 week ago

Description:

The following security vulnerability is detected with protobuf-java library:

Library Vulnerability Severity Status Installed Version Fixed Version Title
com.google.protobuf:protobuf-java (protobuf-java-3.20.3.jar) CVE-2024-7254 HIGH fixed 3.20.3 3.25.5, 4.27.5, 4.28.2 protobuf-java has potential Denial of Service issue

Describe your task(s)

Need to update the version to 3.25.5 in the following standard libraries