[ https://issues.apache.org/jira/browse/ARROW-18302?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17634273#comment-17634273 ]
Raúl Cumplido commented on ARROW-18302: --------------------------------------- Hi [~chaig] thanks for bringing awareness around this topic. We have merged a PR that will be released as part of 10.0.1 that updates the bundled version of openssl that gets included on pyarrow wheels to 3.0.7. > [Python] Is pyarrow vulnerable to CVE-2022-3786? > ------------------------------------------------- > > Key: ARROW-18302 > URL: https://issues.apache.org/jira/browse/ARROW-18302 > Project: Apache Arrow > Issue Type: Bug > Components: Packaging, Python > Affects Versions: 9.0.0 > Reporter: Christina > Assignee: Raúl Cumplido > Priority: Blocker > Labels: pull-request-available > Fix For: 10.0.1, 11.0.0 > > Time Spent: 2h 10m > Remaining Estimate: 0h > > Since pyarrow seems to have no disposition on this bug already, I am curious > if the implementation of openssl included with pyarrow is vulnerable to > [https://nvd.nist.gov/vuln/detail/CVE-2022-3786] > Here is the commit of openssl that this is fixed in: > https://github.com/openssl/openssl/commit/c42165b5706e42f67ef8ef4c351a9a4c5d21639a -- This message was sent by Atlassian Jira (v8.20.10#820010)