Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade com.esotericsoftware:kryo-shaded:jar:4.0.2 to avoid security risk #665

Open
zhudaxi opened this issue Feb 18, 2022 · 3 comments
Open

Comments

@zhudaxi
Copy link

zhudaxi commented Feb 18, 2022

In currently latest version of twitter::chill, kryo-shaded 4.0.2 is used, which has security vulnerability BDSA-2016-1151: Allows DoS via Java Serialization API. And this security risk is fixed in kryo 5.3.0.
Is this possible to upgrade using the higher version kryo?

@rogern
Copy link

rogern commented Mar 28, 2022

+1

@chiavennasca
Copy link

Any updates here? This is showing up in our static analysis security scans.

@johnynek
Copy link
Collaborator

johnynek commented Nov 4, 2022

a PR was begun but abandoned:

#514

PRs are accepted and if the CI can be made green we merge. Unfortunately, this basically a community effort at this time, and my role (note: I left Twitter 7 years ago) is to contribute some time reviewing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants