Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Plaid SDK introduces high and medium security vulnerabilities from com.google.protobuf dependency #244

Open
dmytroKarataiev opened this issue Mar 30, 2023 · 0 comments

Comments

@dmytroKarataiev
Copy link

The problem

Snyk security check found three security vulnerabilities in the Plaid 3.10-3.11 SDKs:
https://security.snyk.io/vuln/SNYK-JAVA-COMGOOGLEPROTOBUF-3167771
https://security.snyk.io/vuln/SNYK-JAVA-COMGOOGLEPROTOBUF-3040281
https://security.snyk.io/vuln/SNYK-JAVA-COMGOOGLEPROTOBUF-3040280

Expected Result

Security vulnerabilities have been fixed in the following dependencies:
Upgrade com.google.protobuf:protobuf-javalite to version 3.16.3, 3.19.6, 3.20.3, 3.21.7 or higher.
Upgrade com.google.protobuf:protobuf-kotlin-lite to version 3.16.3, 3.19.6, 3.20.3, 3.21.7 or higher.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant