Skip to content

Conversation

guptas6est
Copy link

Summary

This PR upgrades the Guava dependency in zookeeper-contrib-zooinspector
from 30.0-jre to 32.1.3-jre.

Motivation

The upgrade addresses the following known vulnerabilities:

  • CVE-2023-2976: Insecure temporary directory creation
  • CVE-2020-8908: Local information disclosure via temporary directory
    created with unsafe permissions

Details

  • Updated <guava.version> property in zookeeper-contrib-zooinspector/pom.xml
    to 32.1.3-jre.
  • Ensures continued compatibility with the project while remediating the
    reported CVEs.
  • Verified build and tests pass successfully after the update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant