Status
Impact
The package explicitly pins protobuf to version 3.2.0 in all upstream releases. To remediate the CVE, upstream must bump the protobuf dependency to at least version 3.7.2. Once upstream integrates this update, we can propagate the change and update our package accordingly.
Status