Skip to content

Commit 133b5bb

Browse files
authored
#76 fixed vulnerability CVE 2024 47561 in org.apache.avro avro (#78)
* Updated version to 2.0.11 * Updated dependencies * Updated changes file
1 parent 5985eec commit 133b5bb

File tree

5 files changed

+125
-118
lines changed

5 files changed

+125
-118
lines changed

dependencies.md

+82-89
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

doc/changes/changelog.md

+1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

doc/changes/changes_2.0.11.md

+31
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
# Parquet for Java 2.0.11, released 2024-10-17
2+
3+
Code name: Fix CVE-2024-47561 in dependency
4+
5+
## Summary
6+
7+
This release fixes vulnerability CVE-2024-47561 by updating transitive dependency `org.apache.avro:avro` via `org.apache.hadoop:hadoop-client`.
8+
9+
## Security
10+
11+
* #76: Fixed vulnerability CVE-2024-47561 in `org.apache.avro:avro`
12+
13+
## Dependency Updates
14+
15+
### Compile Dependency Updates
16+
17+
* Updated `dnsjava:dnsjava:3.6.0` to `3.6.2`
18+
* Removed `io.airlift:aircompressor:0.27`
19+
* Updated `org.apache.avro:avro:1.11.3` to `1.12.0`
20+
* Removed `org.apache.commons:commons-compress:1.26.2`
21+
* Updated `org.apache.parquet:parquet-hadoop:1.14.1` to `1.14.3`
22+
* Updated `org.scala-lang:scala-library:2.13.14` to `2.13.15`
23+
* Removed `org.xerial.snappy:snappy-java:1.1.10.5`
24+
25+
### Test Dependency Updates
26+
27+
* Updated `nl.jqno.equalsverifier:equalsverifier:3.16.1` to `3.17.1`
28+
* Updated `org.hamcrest:hamcrest:2.2` to `3.0`
29+
* Updated `org.junit.jupiter:junit-jupiter:5.10.3` to `5.11.2`
30+
* Updated `org.mockito:mockito-core:5.12.0` to `5.14.2`
31+
* Updated `org.mockito:mockito-junit-jupiter:5.12.0` to `5.14.2`

pk_generated_parent.pom

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

pom.xml

+10-28
Original file line numberDiff line numberDiff line change
@@ -3,38 +3,26 @@
33
<modelVersion>4.0.0</modelVersion>
44
<groupId>com.exasol</groupId>
55
<artifactId>parquet-io-java</artifactId>
6-
<version>2.0.10</version>
6+
<version>2.0.11</version>
77
<name>Parquet for Java</name>
88
<description>This project provides a library that reads Parquet files into Java objects.</description>
99
<url>https://github.com/exasol/parquet-io-java/</url>
1010
<parent>
1111
<artifactId>parquet-io-java-generated-parent</artifactId>
1212
<groupId>com.exasol</groupId>
13-
<version>2.0.10</version>
13+
<version>2.0.11</version>
1414
<relativePath>pk_generated_parent.pom</relativePath>
1515
</parent>
1616
<properties>
17-
<scala.version>2.13.14</scala.version>
17+
<scala.version>2.13.15</scala.version>
1818
<scala.compat.version>2.13</scala.compat.version>
19-
<mockito.version>5.12.0</mockito.version>
19+
<mockito.version>5.14.2</mockito.version>
2020
</properties>
2121
<dependencies>
2222
<dependency>
2323
<groupId>org.apache.parquet</groupId>
2424
<artifactId>parquet-hadoop</artifactId>
25-
<version>1.14.1</version>
26-
</dependency>
27-
<!-- Update transitive dependency of org.apache.parquet:parquet-hadoop to fix CVE-2024-36114 -->
28-
<dependency>
29-
<groupId>io.airlift</groupId>
30-
<artifactId>aircompressor</artifactId>
31-
<version>0.27</version>
32-
</dependency>
33-
<dependency>
34-
<!-- Update transitive dependency of org.apache.parquet:parquet-hadoop to fix CVE-2023-34453, CVE-2023-34454, CVE-2023-34455, CVE-2023-43642 -->
35-
<groupId>org.xerial.snappy</groupId>
36-
<artifactId>snappy-java</artifactId>
37-
<version>1.1.10.5</version>
25+
<version>1.14.3</version>
3826
</dependency>
3927
<dependency>
4028
<groupId>org.apache.hadoop</groupId>
@@ -133,13 +121,7 @@
133121
<!-- Upgrade transitive dependency of org.apache.hadoop:hadoop-client to fix CVE-2023-39410 -->
134122
<groupId>org.apache.avro</groupId>
135123
<artifactId>avro</artifactId>
136-
<version>1.11.3</version>
137-
</dependency>
138-
<dependency>
139-
<!-- Upgrade transitive dependency of org.apache.avro:avro to fix CVE-2023-42503 -->
140-
<groupId>org.apache.commons</groupId>
141-
<artifactId>commons-compress</artifactId>
142-
<version>1.26.2</version>
124+
<version>1.12.0</version>
143125
</dependency>
144126
<!-- Upgrade transitive dependency of org.apache.hadoop:hadoop-client to fix CVE-2024-29131 & CVE-2024-29133 -->
145127
<dependency>
@@ -151,7 +133,7 @@
151133
<dependency>
152134
<groupId>dnsjava</groupId>
153135
<artifactId>dnsjava</artifactId>
154-
<version>3.6.0</version>
136+
<version>3.6.2</version>
155137
</dependency>
156138
<dependency>
157139
<groupId>org.scala-lang</groupId>
@@ -167,7 +149,7 @@
167149
<dependency>
168150
<groupId>org.junit.jupiter</groupId>
169151
<artifactId>junit-jupiter</artifactId>
170-
<version>5.10.3</version>
152+
<version>5.11.2</version>
171153
<scope>test</scope>
172154
</dependency>
173155
<dependency>
@@ -185,7 +167,7 @@
185167
<dependency>
186168
<groupId>org.hamcrest</groupId>
187169
<artifactId>hamcrest</artifactId>
188-
<version>2.2</version>
170+
<version>3.0</version>
189171
<scope>test</scope>
190172
</dependency>
191173
<dependency>
@@ -197,7 +179,7 @@
197179
<dependency>
198180
<groupId>nl.jqno.equalsverifier</groupId>
199181
<artifactId>equalsverifier</artifactId>
200-
<version>3.16.1</version>
182+
<version>3.17.1</version>
201183
<scope>test</scope>
202184
</dependency>
203185
</dependencies>

0 commit comments

Comments
 (0)