Closed wendelfabianchinsamy closed 1 week ago
Uh, what are we using protobuf for in the first place? Is it used by a dependency? Also we're not running jruby or does this dependency run that in the background for it to work?
Uh, what are we using protobuf for in the first place? Is it used by a dependency? Also we're not running jruby or does this dependency run that in the background for it to work?
It is a dependency of apollo-federation (related to GraphQL).
Purpose
When parsing unknown fields in the Protobuf Java Lite and Full library, a maliciously crafted message can cause a StackOverflow error and lead to a program crash.
Reporter: Alexis Challande, Trail of Bits Ecosystem Security Team ecosystem@trailofbits.com
Affected versions: This issue affects all versions of both the Java full and lite Protobuf runtimes, as well as Protobuf for Kotlin and JRuby, which themselves use the Java Protobuf runtime.
closes: https://github.com/datacite/lupo/issues/1246
Approach
Open Questions and Pre-Merge TODOs
Learning
Types of changes
[ ] Bug fix (non-breaking change which fixes an issue)
[ ] New feature (non-breaking change which adds functionality)
[ ] Breaking change (fix or feature that would cause existing functionality to change)
Reviewer, please remember our guidelines: