You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@beam.apache.org by "Mohinuddin (Jira)" <ji...@apache.org> on 2022/03/06 22:45:00 UTC
[jira] [Created] (BEAM-14054) Vulnerabilities in org.apache.avro dependencies
Mohinuddin created BEAM-14054:
---------------------------------
Summary: Vulnerabilities in org.apache.avro dependencies
Key: BEAM-14054
URL: https://issues.apache.org/jira/browse/BEAM-14054
Project: Beam
Issue Type: Bug
Components: dependencies, sdk-java-core
Affects Versions: 2.37.0
Reporter: Mohinuddin
The current Avro jar version 1.8.2 has multiple vulnerabilities. This needs to be upgraded to version 1.11.0
[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36090]
[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35517]
[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35516]
[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35515]
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10172
--
This message was sent by Atlassian Jira
(v8.20.1#820001)