You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@beam.apache.org by "Kenneth Knowles (Jira)" <ji...@apache.org> on 2022/03/17 17:41:00 UTC

[jira] [Updated] (BEAM-14054) Vulnerabilities in org.apache.avro dependencies

     [ https://issues.apache.org/jira/browse/BEAM-14054?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Kenneth Knowles updated BEAM-14054:
-----------------------------------
    Status: Open  (was: Triage Needed)

> Vulnerabilities in org.apache.avro dependencies
> -----------------------------------------------
>
>                 Key: BEAM-14054
>                 URL: https://issues.apache.org/jira/browse/BEAM-14054
>             Project: Beam
>          Issue Type: Bug
>          Components: dependencies, sdk-java-core
>    Affects Versions: 2.37.0
>            Reporter: Mohinuddin
>            Priority: P2
>
> The current Avro jar version 1.8.2 has multiple vulnerabilities. This needs to be upgraded to version 1.11.0
> [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36090]
> [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35517]
> [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35516]
> [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35515]
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10172



--
This message was sent by Atlassian Jira
(v8.20.1#820001)