From 5f25a2ccc1643e2c1768b50194701a503d9ad168 Mon Sep 17 00:00:00 2001 From: Maxim Lapan Date: Mon, 23 Sep 2024 14:31:44 +0200 Subject: [PATCH] Fixes in docs, scope in pom --- doc/changes/changes_2.0.8.md | 6 +++--- pom.xml | 9 +++++++++ 2 files changed, 12 insertions(+), 3 deletions(-) diff --git a/doc/changes/changes_2.0.8.md b/doc/changes/changes_2.0.8.md index 5f83287..042ae37 100644 --- a/doc/changes/changes_2.0.8.md +++ b/doc/changes/changes_2.0.8.md @@ -1,11 +1,11 @@ -# Spark Connector Common Java 2.0.8, released 2024-09-24 +# Spark Connector Common Java 2.0.8, released 2024-09-23 Code name: Fixed vulnerability CVE-2024-7254 in com.google.protobuf:protobuf-java:jar:3.19.6:provided ## Summary -This release fixes vulnerability CVE-2024-7254 in com.google.protobuf:protobuf-java:jar:3.19.6:provided +This release fixes vulnerability CVE-2024-7254 in com.google.protobuf:protobuf-java:jar:3.19.6:provided which could lead to unbounded recursion. -## Features +## Security * #41: CVE-2024-7254: com.google.protobuf:protobuf-java:jar:3.19.6:provided diff --git a/pom.xml b/pom.xml index a9108a4..26716f5 100644 --- a/pom.xml +++ b/pom.xml @@ -80,54 +80,63 @@ org.apache.commons commons-compress 1.26.2 + provided org.xerial.snappy snappy-java 1.1.10.5 + provided org.apache.ivy ivy 2.5.2 + provided org.apache.zookeeper zookeeper 3.9.2 + provided org.apache.avro avro 1.11.3 + provided joda-time joda-time 2.12.7 + provided io.netty netty-all 4.1.111.Final + provided org.codehaus.janino janino 3.1.12 + provided com.google.protobuf protobuf-java 3.25.5 + provided