Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Avro version to 1.11.0 #409

Open
esikgabi opened this issue Jan 5, 2022 · 3 comments
Open

Upgrade Avro version to 1.11.0 #409

esikgabi opened this issue Jan 5, 2022 · 3 comments

Comments

@esikgabi
Copy link

esikgabi commented Jan 5, 2022

The 1.10.2 Avro version has several vulnerabilities AVRO-3227 which are fixed in the 1.11.0 version AVRO-3215.

@ewencp
Copy link
Contributor

ewencp commented Jan 6, 2022

The dependency version info can be lifted up into this pom.xml, but we already have commons-compress at 1.21 in ksqldb, schema-registry, connect-replicator, control-center, etc. I think that has also been backported to all supported versions.

A version upgrade for Avro needs to be handled carefully as we'd need to check for any incompatibilities, especially in backporting to earlier versions. Given the issue is already addressed by pinning the commons-compress version, I'm not sure we'd want to do more here other than updating master to the new version after evaluating any potential compatibility issues.

@esikgabi
Copy link
Author

esikgabi commented Feb 9, 2022

It seems the avro version was upgraded: a4eed43
Which release will contain this change?
Is there any place where we can check the planned releases? (time and contained features/fixes)
Thanks

@junquero
Copy link

Avro version 1.11.0 has a transitive dependency with jackson-databind that has the CVE-2020-36518 which has been updated in avro 1.11.1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants