legacy-knowledge-base
公開されました Jun. 30, 2025

Google Guava バージョン 1.0 から 32 に関するセキュリティ問題

written-by

Adrienne Lao

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

legacy-article

learn-legacy-article-disclaimer-text

問題

  • Google Guavaには、1.0から31.1までのバージョンに影響する脆弱性が存在します。 Liferayは現在Guavaにバンドルされている。 と報告されている。
    osb-distributed-messaging-google-pubsub-connector
    は、既知の脆弱性が存在するGuava 30.1.1への依存を宣言しています。 CVE-2023-2976

環境

  • Liferay 7.2+

解像度

  • 脆弱性を回避するためには、Guavaのバージョンが32以上のLiferay環境にアップグレードすることが推奨される。 Liferay 7.4 U92はGuava 32.0.1を使用しており、この脆弱性を緩和する最も早いアップデートです。
  • Liferayバンドルが使用しているGuavaのバージョンを確認するには、 Liferay HomeからLiferayターミナルで以下のコマンドを実行します。
  • grep -r 'guava'
did-this-article-resolve-your-issue

legacy-knowledge-base