[ https://issues.apache.org/jira/browse/HIVE-28577?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17892520#comment-17892520 ]
Ayush Saxena commented on HIVE-28577: ------------------------------------- Committed to master. Thanx [~Aggarwal_Raghav] for the contribution!!! > Upgrade protobuf version to 3.25.5 to fix CVE > --------------------------------------------- > > Key: HIVE-28577 > URL: https://issues.apache.org/jira/browse/HIVE-28577 > Project: Hive > Issue Type: Improvement > Security Level: Public(Viewable by anyone) > Reporter: Raghav Aggarwal > Assignee: Raghav Aggarwal > Priority: Minor > Labels: pull-request-available > > Protobuf 3.24.4. has a CVE: > [CVE-2024-7254|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7254] > Also, tez (master branch) has also moved to 3.25.5 version of protobuf. -- This message was sent by Atlassian Jira (v8.20.10#820010)