Skip to content

[v13]: Update gravitational/protobuf fork tag (#26373)#26488

Merged
jentfoo merged 1 commit intobranch/v13from
jent/protobuf_upgrade-v13
May 18, 2023
Merged

[v13]: Update gravitational/protobuf fork tag (#26373)#26488
jentfoo merged 1 commit intobranch/v13from
jent/protobuf_upgrade-v13

Conversation

@jentfoo
Copy link
Copy Markdown
Contributor

@jentfoo jentfoo commented May 17, 2023

Backport of PR: #26373 to address CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-3121

* Update `gravitational/protobuf` fork tag

Previously we were not referencing a tag, instead we were referenced to a commit on this branch: https://github.com/gravitational/protobuf/tree/dmitri/merge-values

Previously versioned `1.3.2` it was thought that this branch contained the fix for `Skippy Peanut Butter` CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-3121

However that was not the case, so the following was performed:
* A `teleport` branch was created on `protobuf` from the upstream v1.3.2 tag
* Our custom commits were cherry-picked in (the Clone Merger functionality added, codeql config, and dependency-review config)
* It was pushed as tag `v1.3.2-1` to our fork (as seen in this change)

* Update protobuf tag to v1.3.2-teleport.1
@jentfoo jentfoo added security Security Issues sec-type-dos Security Vulnerability - Denial of Service labels May 17, 2023
@jentfoo jentfoo self-assigned this May 17, 2023
@jentfoo jentfoo added this pull request to the merge queue May 18, 2023
Merged via the queue into branch/v13 with commit 1814d0d May 18, 2023
@jentfoo jentfoo deleted the jent/protobuf_upgrade-v13 branch May 18, 2023 16:14
@r0mant r0mant mentioned this pull request Jul 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport sec-type-dos Security Vulnerability - Denial of Service security Security Issues size/sm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants