Skip to content

Bump org.apache.commons.commons-compress from 1.24.0 to 1.26.0#8513

Closed
gb wants to merge 1 commit intotestcontainers:mainfrom
gb:main
Closed

Bump org.apache.commons.commons-compress from 1.24.0 to 1.26.0#8513
gb wants to merge 1 commit intotestcontainers:mainfrom
gb:main

Conversation

@gb
Copy link
Copy Markdown

@gb gb commented Apr 5, 2024

I understand the instructions ask not to open a pull request to update only a version dependency. However, I don't see a PR opened for this specific dependency, and there is a serious vulnerability in the current version used.

Fixed in Apache Commons Compress 1.26.0
Important: Denial of Service CVE-2024-25710
This affects version 1.3 through 1.25.0.
This denial of service is caused by an infinite loop reading a corrupted DUMP file.
Users are recommended to upgrade to version 1.26.0 which fixes the issue.

Moderate: Denial of Service CVE-2024-26308
You can get an OutOfMemoryError unpacking a broken Pack200 file.
This issue affects Commons Compress 1.21 before 1.26.0.
Users are recommended to upgrade to version 1.26.0 which fixes the issue.

@gb gb requested a review from a team April 5, 2024 18:46
@gb gb changed the title bump-up commons-compress to 1.26.0 bump-up commons-compress from 1.24.0 to 1.26.0 Apr 5, 2024
@gb gb changed the title bump-up commons-compress from 1.24.0 to 1.26.0 Bump commons-compress from 1.24.0 to 1.26.0 Apr 5, 2024
@gb gb changed the title Bump commons-compress from 1.24.0 to 1.26.0 Bump org.apache.commons.commons-compress from 1.24.0 to 1.26.0 Apr 5, 2024
@eddumelendez
Copy link
Copy Markdown
Member

Thanks for the contribution, please check #8354 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants