-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2023-2976 has not been fixed on f40 #129
Comments
First, Fedora bugs are tracked in Red Hat Bugzilla at https://bugzilla.redhat.com/.
We are planning to fix the issue in Fedora, but it has moderate severity, so it was preempted by more important work. As for javapackages-bootstrap, the use of guava is very limited and therefore has low severity. It will be fixed eventually by updating Guava to newer version, but it's not a priority for the project. |
Thanks. |
Hi Fedora Java Team,
As it failed during the compile time/compiler tool, It may be jsr-305 version incompatibility with guava that is causing it (EDIT: looks like this is fine 3.0.2). I have updated other sources which did not have this issue. Any help is appreciated.
|
Using jurand solves this. Probably new annotations were added which are not replaced I guess. |
Hello, a vulnerability CVE-2023-2976 was recently reported in Guava. The upstream community suggests upgrading to version 32.0.1, but the latest version in Fedora is still 31.1 and there is no patch to fix this vulnerability in Fedora. May I ask why Fedora has not fixed this vulnerability?
References:
The text was updated successfully, but these errors were encountered: