Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update AWS libraries to pick up a version of fast-xml-parser that addresses CVE-2023-34104. #37

Merged
merged 1 commit into from Jul 7, 2023

Conversation

awhittier-cribl
Copy link
Contributor

Hi!

We would like to update the versions of the AWS SDK to one that depends on fast-xml-parser 4.2.5 instead of 4.1.2. 4.1.2 is vulnerable to https://www.cve.org/CVERecord?id=CVE-2023-34104, while 4.2.5 is not.

I ran the simple example against an MSK cluster we have and it authenticated without any issues. If there are any other changes you'd like or steps you want me to follow, just let me know.

Thanks!

@awhittier-cribl
Copy link
Contributor Author

I will be away for the week of July 10th so if there are any comments/questions/whatever feel free to leave them here and I'll check in when I'm back.

@jmaver-plume jmaver-plume self-requested a review July 7, 2023 19:15
@jmaver-plume jmaver-plume merged commit b2cdc33 into jmaver-plume:main Jul 7, 2023
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants