Skip to content

[fix][sec] bump snakeyaml to 1.31 fix CVE-2022-25857 - #17457

Merged
Jason918 merged 3 commits into
apache:masterfrom
tisonkun:fix-CVE-2022-25857
Sep 5, 2022
Merged

[fix][sec] bump snakeyaml to 1.31 fix CVE-2022-25857#17457
Jason918 merged 3 commits into
apache:masterfrom
tisonkun:fix-CVE-2022-25857

Conversation

@tisonkun

@tisonkun tisonkun commented Sep 5, 2022

Copy link
Copy Markdown
Member

Does this pull request potentially affect one of the following parts:

If yes was chosen, please highlight the changes

  • Dependencies (does it add or upgrade a dependency): (yes)

Fix CVEs.

  • doc-not-needed

Signed-off-by: tison <wander4096@gmail.com>
@github-actions github-actions Bot added the doc-not-needed Your PR changes do not impact docs label Sep 5, 2022
@tisonkun

tisonkun commented Sep 5, 2022

Copy link
Copy Markdown
Member Author

This patch can still fail on OWASP due to CVE-2021-3565 fp. See the report for details or see #17458 as a batch patch.

Signed-off-by: tison <wander4096@gmail.com>

@zymap zymap left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you! Please help to update the license file for pulsar and lib/presto as well.

@zymap zymap added this to the 2.11.0 milestone Sep 5, 2022
@zymap
zymap requested a review from Technoboy- September 5, 2022 01:15
Signed-off-by: tison <wander4096@gmail.com>
@tisonkun

tisonkun commented Sep 5, 2022

Copy link
Copy Markdown
Member Author

@zymap nice catch! Updated.

@zymap

zymap commented Sep 5, 2022

Copy link
Copy Markdown
Member

Thank you!

@tisonkun

tisonkun commented Sep 5, 2022

Copy link
Copy Markdown
Member Author

/pulsarbot run-failure-checks

@tisonkun

tisonkun commented Sep 5, 2022

Copy link
Copy Markdown
Member Author

@zymap @Technoboy- @Jason918 This patch is ready to merge. Then I'll rebase #17458 onto this one :)

@Jason918
Jason918 merged commit 3ea478a into apache:master Sep 5, 2022
@tisonkun
tisonkun deleted the fix-CVE-2022-25857 branch September 5, 2022 04:24
tisonkun added a commit to tisonkun/pulsar that referenced this pull request Sep 5, 2022
nicoloboschi pushed a commit to datastax/pulsar that referenced this pull request Sep 6, 2022
nicoloboschi pushed a commit that referenced this pull request Sep 6, 2022
@pjfanning

Copy link
Copy Markdown
Member

snakeyaml v1.32 fixes a 2nd similar issue - GHSA-9w3m-gqgf-c4p9

@congbobo184

Copy link
Copy Markdown
Contributor

could you please cherry-pick this PR to branch-2.9? thanks.

@tisonkun

Copy link
Copy Markdown
Member Author

@congbobo184 I think I can pick only #17779 that bump to 1.32. I'm doing this now :)

@congbobo184 congbobo184 added the cherry-picked/branch-2.9 Archived: 2.9 is end of life label Nov 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants