[ACTION REQUIRED] Protobuf Java users, please update to our latest release

72 views
Skip to first unread message

Derek Perez

unread,
Jan 6, 2022, 12:15:55 PM1/6/22
to Protocol Buffers
Hello everyone,

If you are using protobuf-java, Kotlin, or our JRuby gem (google-protobuf), please update to our latest release, published yesterday.
More information about this advisory can be found here:

Thanks!
- Derek on behalf of the Protobuf Team

Marc Gravell

unread,
Jan 6, 2022, 1:01:11 PM1/6/22
to Derek Perez, Protocol Buffers
I notice that the advisory is scant on details at the moment; is there any mechanism for non-Google protobuf library authors to request additional details to see whether our own implementations may be vulnerable to the attack? Thanks

--
You received this message because you are subscribed to the Google Groups "Protocol Buffers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to protobuf+u...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/protobuf/CAJGs%2BiKxiTSGxh872Rh7sv1pzGENX53WaHfGQnSoRzJROoApSA%40mail.gmail.com.


--
Regards,

Marc

Derek Perez

unread,
Jan 6, 2022, 1:20:51 PM1/6/22
to Marc Gravell, Protocol Buffers
As I understand it, reproduction details will be made available in the next 30 days.
Reply all
Reply to author
Forward
0 new messages