[ https://issues.apache.org/jira/browse/FLINK-32371?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Matthias Pohl resolved FLINK-32371. ----------------------------------- Fix Version/s: 1.16.3 1.17.2 Resolution: Fixed > Bump snappy-java to 1.1.10.1 > ---------------------------- > > Key: FLINK-32371 > URL: https://issues.apache.org/jira/browse/FLINK-32371 > Project: Flink > Issue Type: Improvement > Components: Build System > Affects Versions: 1.16.2, 1.18.0, 1.17.1 > Reporter: Ryan Skraba > Assignee: Ryan Skraba > Priority: Major > Labels: pull-request-available > Fix For: 1.18.0, 1.16.3, 1.17.2 > > > There is a CVE in all versions of snappy prior to 1.1.10.1 > https://nvd.nist.gov/vuln/detail/CVE-2023-34455 -- This message was sent by Atlassian Jira (v8.20.10#820010)