Skip to content

CVE-2024-24786 #349

Open
Open
@lewijw

Description

@lewijw

There is a security issue with google.golang.org/protobuf:

https://nvd.nist.gov/vuln/detail/CVE-2024-24786

It was fixed with this commit:
protocolbuffers/protobuf-go@f01a588

So, google.golang.org/protobuf should be upgraded to 1.33.0.
Also, github.com/golang/protobuf version 1.5.4 uses the fixed version of google.golang.org/protobuf. That should be upgraded too.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions