Переглянути джерело

ZOOKEEPER-4707: Upgrade snappy-java to address multiple CVEs (#2014)

Address multiple CVEs:
CVE-2023-34453
CVE-2023-34454
CVE-2023-34455

See https://github.com/xerial/snappy-java/releases/tag/v1.1.10.1
Lari Hotari 1 рік тому
батько
коміт
4661437a16

+ 1 - 1
pom.xml

@@ -562,7 +562,7 @@
     <jetty.version>9.4.51.v20230217</jetty.version>
     <jackson.version>2.15.2</jackson.version>
     <jline.version>2.14.6</jline.version>
-    <snappy.version>1.1.9.1</snappy.version>
+    <snappy.version>1.1.10.1</snappy.version>
     <kerby.version>2.0.0</kerby.version>
     <bouncycastle.version>1.60</bouncycastle.version>
     <commons-collections.version>4.4</commons-collections.version>

+ 0 - 0
zookeeper-server/src/main/resources/lib/snappy-java-1.1.9.1.jar_LICENSE.txt → zookeeper-server/src/main/resources/lib/snappy-java-1.1.10.1.jar_LICENSE.txt