Vulnerability in snappy-java-1.1.10.1 [HZ-3398]
envgap__hazelcast__hazelcast-25595
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
f31272b3c21b991411cdb3b6fe78d6cec6faf2fa- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
hazelcast/hazelcast #25595 · read the original issue
[CVE-2023-43642](https://nvd.nist.gov/vuln/detail/CVE-2023-43642) ``` Referenced In Projects/Scopes: hazelcast-jet-files-s3:compile hazelcast-jet-hadoop-dist:compile hazelcast-jet-cdc-debezium:runtime hazelcast-distribution:compile hazelcast-jet-kafka:runtime hazelcast-jet-files-gcs:compile hazelcast-jet-kafka-connect:runtime hazelcast-jet-files-azure:compile hazelcast-jet-hadoop-all:compile ``` Affects: 5.1.z/5.2.z/5.3.z/master Fix is available: [Releases · xerial/snappy-java](https://github.com/xerial/snappy-java/releases)
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]