Title: Security vulnerability of python package: pyarrow (CVE-2023-47248) · Issue #3832 · feast-dev/feast · GitHub
Open Graph Title: Security vulnerability of python package: pyarrow (CVE-2023-47248) · Issue #3832 · feast-dev/feast
X Title: Security vulnerability of python package: pyarrow (CVE-2023-47248) · Issue #3832 · feast-dev/feast
Description: As described by this article regarding CVE-2023-47248: https://securityonline.info/cve-2023-47248-pyarrow-arbitrary-code-execution-vulnerability-a-critical-threat-to-data-analysts/ https://osv.dev/vulnerability/GHSA-5wvp-7f3h-6wmm Curren...
Open Graph Description: As described by this article regarding CVE-2023-47248: https://securityonline.info/cve-2023-47248-pyarrow-arbitrary-code-execution-vulnerability-a-critical-threat-to-data-analysts/ https://osv.dev/...
X Description: As described by this article regarding CVE-2023-47248: https://securityonline.info/cve-2023-47248-pyarrow-arbitrary-code-execution-vulnerability-a-critical-threat-to-data-analysts/ https://osv.dev/...
Opengraph URL: https://github.com/feast-dev/feast/issues/3832
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Security vulnerability of python package: pyarrow (CVE-2023-47248) ","articleBody":"As described by this article regarding CVE-2023-47248: https://securityonline.info/cve-2023-47248-pyarrow-arbitrary-code-execution-vulnerability-a-critical-threat-to-data-analysts/\r\n\r\nhttps://osv.dev/vulnerability/GHSA-5wvp-7f3h-6wmm\r\n\r\nCurrent Pyarrow version in setup.py: \"pyarrow\u003e=4,\u003c12\",\r\n\r\nOne conflict from a third-party lib:\r\n1. Snowflake dependency: pyarrow\u003c10.1.0,\u003e=10.0.1 (from snowflake-connector-python[pandas]==3.4.1-\u003efeast (setup.py)). The Snowflake developers are fixing this: https://github.com/snowflakedb/snowflake-connector-python/issues/1802\r\n\r\nWe need to update the pyarrow version to 14.0.1 \r\n\r\nor apply the hotfix: https://pypi.org/project/pyarrow-hotfix/","author":{"url":"https://github.com/shuchu","@type":"Person","name":"shuchu"},"datePublished":"2023-11-11T00:54:27.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":1},"url":"https://github.com/3832/feast/issues/3832"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:53335a81-f20b-f18a-0a06-d28608670500 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | A31C:243FA0:102442B:150DBA1:697426F8 |
| html-safe-nonce | b77adde7dde7e3b6efb8f05be7b2836851a295f9e93447f0a3f5ca4b65de7a6e |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBMzFDOjI0M0ZBMDoxMDI0NDJCOjE1MERCQTE6Njk3NDI2RjgiLCJ2aXNpdG9yX2lkIjoiMzgzMTE2NDQwMDkyODMwMjg0MCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 9c6138df64c7ab4c40af1e9f44a7bc5eb5098db1b366a499376f55f085011c2b |
| hovercard-subject-tag | issue:1988618105 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/feast-dev/feast/3832/issue_layout |
| twitter:image | https://opengraph.githubassets.com/b159d1a4ed506da21ec177ce6cca196648707a6eed424dd1ca14e24dfbf0f631/feast-dev/feast/issues/3832 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/b159d1a4ed506da21ec177ce6cca196648707a6eed424dd1ca14e24dfbf0f631/feast-dev/feast/issues/3832 |
| og:image:alt | As described by this article regarding CVE-2023-47248: https://securityonline.info/cve-2023-47248-pyarrow-arbitrary-code-execution-vulnerability-a-critical-threat-to-data-analysts/ https://osv.dev/... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | shuchu |
| hostname | github.com |
| expected-hostname | github.com |
| None | 447dc9917c3d68d647a01abfdefe55ec7ee1785922136c1d8395dbb3ab6d57b9 |
| turbo-cache-control | no-preview |
| go-import | github.com/feast-dev/feast git https://github.com/feast-dev/feast.git |
| octolytics-dimension-user_id | 57027613 |
| octolytics-dimension-user_login | feast-dev |
| octolytics-dimension-repository_id | 161133770 |
| octolytics-dimension-repository_nwo | feast-dev/feast |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 161133770 |
| octolytics-dimension-repository_network_root_nwo | feast-dev/feast |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 8dad7bdfecbe3eaa97ac4e632d6b47e2b23e81d9 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width