Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sec vul: CVE-2023-2976 from google-guava dep #950

Closed
amaciejk opened this issue Jul 25, 2023 · 5 comments
Closed

Sec vul: CVE-2023-2976 from google-guava dep #950

amaciejk opened this issue Jul 25, 2023 · 5 comments

Comments

@amaciejk
Copy link

Can you update the version of google guava used to 32.0.1 or higher to resolve CVE-2023-2976 for the next release?

https://nvd.nist.gov/vuln/detail/CVE-2023-2976
https://mvnrepository.com/artifact/com.google.googlejavaformat/google-java-format/1.17.0
https://mvnrepository.com/artifact/com.google.guava/guava

copybara-service bot pushed a commit to google/turbine that referenced this issue Jul 27, 2023
This was referenced Jul 27, 2023
copybara-service bot pushed a commit that referenced this issue Jul 27, 2023
#950

PiperOrigin-RevId: 551366256
copybara-service bot pushed a commit that referenced this issue Jul 27, 2023
#950

PiperOrigin-RevId: 551370402
copybara-service bot pushed a commit to google/turbine that referenced this issue Jul 27, 2023
@jaguilar-atl
Copy link

It looks like this change is already in the master branch.
https://github.com/google/google-java-format/blob/master/pom.xml#L89

Is there an estimated timeline for when the next release will be?

@raghav-deepsource
Copy link

It would be great if a patch release can be made for this change, please do expedite it.

@gregallen
Copy link

Another vote for this - this issue prevents the intellij plugin from being used in a corporate environment

treblereel pushed a commit to treblereel/turbine that referenced this issue Sep 28, 2023
@cushon
Copy link
Collaborator

cushon commented Oct 2, 2023

I pushed a release that includes the Guava dependency update: https://github.com/google/google-java-format/releases/tag/v1.18.0

@gregallen
Copy link

The IntelliJ plugin needs to be updated to use new version and released

It is still referencing 1.17.0

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants