Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-7254 potential Denial of Service issue in protobuf-java #1086

Open
robert-gdv opened this issue Oct 2, 2024 · 3 comments
Open

CVE-2024-7254 potential Denial of Service issue in protobuf-java #1086

robert-gdv opened this issue Oct 2, 2024 · 3 comments

Comments

@robert-gdv
Copy link

Sonatype reports CVE-2024-7254 on io.prometheus : prometheus-metrics-shaded-protobuf with a CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Score of 8.7.

It is reported, that all Versions of prometheus-metrics-shaded-protobuf until 1.3.1 included are affected.
There is currently no unaffected Version of prometheus-metrics-shaded-protobuf available while the unshaded library protobuf-java was already fixed.

See also GHSA-735f-pc8j-v9w8

@robert-gdv
Copy link
Author

Apparently fixed in #1008
I am waiting for a release.

@robert-gdv
Copy link
Author

On the other hand: That was an automated update. I am not sure that dependabot understands the shading.
Shouldn't it update also the protobuf.version.string variable?

@zeitlinger
Copy link
Member

I've created #1063 to address this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants