microsoft / durabletask-java

Java SDK for Durable Functions and the Durable Task Framework
MIT License
14 stars 7 forks source link

Vulnerability issue #175

Closed kaibocai closed 1 year ago

kaibocai commented 1 year ago

Customer report: The latest version of durable task package available i.e. 1.4.0 contains these CVEs due to older version of protobuf and google guava dependency present in it. Here are the related CVEs : CVE-2022-3171, CVE-2022-3509, CVE-2022-3510, CVE-2023-2976.

There are a few more CVEs can be found at https://mvnrepository.com/artifact/com.microsoft/durabletask-client/1.4.0