Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Fix CVE-2024-45384 and CVE-2024-45537 druid-processing version upgrade #23949

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

mehradpk
Copy link

@mehradpk mehradpk commented Nov 5, 2024

Description

Upgrade druid-processing to version 1.11.4 to resolve CVE-2024-45384 and CVE-2024-45537
Upgrade commons-compress to version 1.26.0
Upgrade commons-codec to version 1.16.1
Upgrade net.java.dev.jna:jna to version 5.13.0
Upgrade com.github.luben:zstd-jni to version 1.5.2-3
Remove druid-core as it has been consolidated into druid-processing since Apache Druid 26.0.0

Motivation and Context

This upgrade was created to deal with CVEs found in lower versions

Impact

None

Release Notes

== RELEASE NOTES ==

General Changes
* Upgrade druid-processing to version 1.11.4 :pr:`23949`
* Upgrade commons-compress to version 1.26.0 :pr:`23949`
* Upgrade commons-codec to version 1.16.1 :pr:`23949`
* Upgrade net.java.dev.jna:jna to version 5.13.0 :pr:`23949`
* Upgrade com.github.luben:zstd-jni to version 1.5.2-3 :pr:`23949`
* Remove druid-core as it has been consolidated into druid-processing since Apache Druid 26.0.0 :pr:`23949`

@mehradpk mehradpk requested a review from a team as a code owner November 5, 2024 07:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant