Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-36114 #1810

Closed
joewragg opened this issue Jun 25, 2024 · 0 comments · Fixed by #1831
Closed

CVE-2024-36114 #1810

joewragg opened this issue Jun 25, 2024 · 0 comments · Fixed by #1831
Assignees
Labels
security 🚨 Security-related issues

Comments

@joewragg
Copy link

Scope

pom.xml

Report Link

https://avd.aquasec.com/nvd/cve-2024-36114

Dependency affected

io.airlift:aircompressor (ors.jar)

Proposed solution / further info

Library Vulnerability Severity Status Installed Version Fixed Version Title
io.airlift:aircompressor (ors.jar) CVE-2024-36114 HIGH fixed 0.20 0.27 Decompressors can crash the JVM and leak memory content in Aircompressor https://avd.aquasec.com/nvd/cve-2024-36114
@joewragg joewragg added the security 🚨 Security-related issues label Jun 25, 2024
@takb takb self-assigned this Jul 30, 2024
@takb takb mentioned this issue Jul 30, 2024
13 tasks
@takb takb closed this as completed in #1831 Aug 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security 🚨 Security-related issues
Projects
No open projects
Status: Awaiting release
Development

Successfully merging a pull request may close this issue.

2 participants