Siddharth R created FLINK-36537:
-----------------------------------

             Summary: Bump snappy-java from 1.1.10.4 to 1.1.10.7
                 Key: FLINK-36537
                 URL: https://issues.apache.org/jira/browse/FLINK-36537
             Project: Flink
          Issue Type: Improvement
            Reporter: Siddharth R

The current version has vulnerability in the dependant package, bumping it to 
the latest version will remediate.

*Vulnerabilities from dependencies:*
[CVE-2024-23454|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23454]
[CVE-2022-26612|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26612]

Package details:
[https://mvnrepository.com/artifact/org.xerial.snappy/snappy-java/1.1.10.7]


 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to