slfan1989 commented on PR #345:
URL: https://github.com/apache/tez/pull/345#issuecomment-2094555633

   @abstractdog @Aggarwal-Raghav @BilwaST Thank you for paying attention to 
this pr! The reason I want to upgrade protobuf is because there are some CVE 
vulnerabilities in lower versions of protobuf, so I try to upgrade protobuf to 
a higher version to solve related issues.
   
   Some known protobuf vulnerabilities:
   https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3171
   https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3509
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to