Skip to content

Commit fd7e0b4

Browse files
committed
[fix][sec] Upgrade Avro to 1.11.4 to address CVE-2024-47561 (#23394)
1 parent c089aff commit fd7e0b4

File tree

3 files changed

+5
-5
lines changed

3 files changed

+5
-5
lines changed

Diff for: distribution/server/src/assemble/LICENSE.bin.txt

+2-2
Original file line numberDiff line numberDiff line change
@@ -494,8 +494,8 @@ The Apache Software License, Version 2.0
494494
* zt-zip
495495
- org.zeroturnaround-zt-zip-1.17.jar
496496
* Apache Avro
497-
- org.apache.avro-avro-1.11.3.jar
498-
- org.apache.avro-avro-protobuf-1.11.3.jar
497+
- org.apache.avro-avro-1.11.4.jar
498+
- org.apache.avro-avro-protobuf-1.11.4.jar
499499
* Apache Curator
500500
- org.apache.curator-curator-client-5.1.0.jar
501501
- org.apache.curator-curator-framework-5.1.0.jar

Diff for: pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -146,7 +146,7 @@ flexible messaging model and an intuitive client API.</description>
146146
<kafka-client.version>2.7.2</kafka-client.version>
147147
<rabbitmq-client.version>5.1.1</rabbitmq-client.version>
148148
<aws-sdk.version>1.12.262</aws-sdk.version>
149-
<avro.version>1.11.3</avro.version>
149+
<avro.version>1.11.4</avro.version>
150150
<joda.version>2.10.5</joda.version>
151151
<jclouds.version>2.5.0</jclouds.version>
152152
<guice.version>5.1.0</guice.version>

Diff for: pulsar-sql/presto-distribution/LICENSE

+2-2
Original file line numberDiff line numberDiff line change
@@ -381,8 +381,8 @@ The Apache Software License, Version 2.0
381381
* Apache XBean :: Reflect
382382
- xbean-reflect-3.4.jar
383383
* Avro
384-
- avro-1.11.3.jar
385-
- avro-protobuf-1.11.3.jar
384+
- avro-1.11.4.jar
385+
- avro-protobuf-1.11.4.jar
386386
* Caffeine
387387
- caffeine-2.9.1.jar
388388
* Javax

0 commit comments

Comments
 (0)