Skip to content

Play-Services Guava Vulnerability #7494

@hammond-mike-ao

Description

@hammond-mike-ao

Issue

There are currently a couple vulnerabilities (CVE-2023-2976, CVE-2020-8908) stemming from the play-services-measurement-api:23.0.0 dependency used in the com.google.firebase:firebase-analytics:23.0.0 library due to an outdated version of Guava being used. Are there any plans to update this Play Services library to use a newer version of Guava to resolve the vulnerability? If not, are there any concerns with clients overriding the version of Guava used?

Affected Dependencies:

play-services-measurement-api:23.0.0
play-services-measurement-impl:23.0.0

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions