Skip to content

Commit 3acdbfe

Browse files
authored
Updating dependencies to get rid of CVEs brought in with kafka and log4j-1.2 libs (#13726)
CVE-2020-27218, CVE-2021-38153, CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105, CVE-2020-9488, CVE-2019-17571, CVE-2021-4104
1 parent 5718d9d commit 3acdbfe

File tree

8 files changed

+62
-2
lines changed

8 files changed

+62
-2
lines changed

pom.xml

+2-2
Original file line numberDiff line numberDiff line change
@@ -139,7 +139,7 @@ flexible messaging model and an intuitive client API.</description>
139139
<hbc-core.version>2.2.0</hbc-core.version>
140140
<cassandra-driver-core.version>3.6.0</cassandra-driver-core.version>
141141
<aerospike-client.version>4.4.8</aerospike-client.version>
142-
<kafka-client.version>2.7.0</kafka-client.version>
142+
<kafka-client.version>2.7.2</kafka-client.version>
143143
<rabbitmq-client.version>5.1.1</rabbitmq-client.version>
144144
<aws-sdk.version>1.11.774</aws-sdk.version>
145145
<avro.version>1.10.2</avro.version>
@@ -150,7 +150,7 @@ flexible messaging model and an intuitive client API.</description>
150150
<postgresql-jdbc.version>42.2.24</postgresql-jdbc.version>
151151
<clickhouse-jdbc.version>0.3.2</clickhouse-jdbc.version>
152152
<mariadb-jdbc.version>2.6.0</mariadb-jdbc.version>
153-
<hdfs-offload-version3>3.3.0</hdfs-offload-version3>
153+
<hdfs-offload-version3>3.3.1</hdfs-offload-version3>
154154
<elasticsearch.version>7.9.1</elasticsearch.version>
155155
<presto.version>332</presto.version>
156156
<scala.binary.version>2.13</scala.binary.version>

pulsar-io/debezium/core/pom.xml

+6
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,12 @@
6666
<groupId>org.apache.kafka</groupId>
6767
<artifactId>connect-runtime</artifactId>
6868
<version>${kafka-client.version}</version>
69+
<exclusions>
70+
<exclusion>
71+
<groupId>org.apache.kafka</groupId>
72+
<artifactId>kafka-log4j-appender</artifactId>
73+
</exclusion>
74+
</exclusions>
6975
</dependency>
7076

7177
<dependency>

pulsar-io/hbase/pom.xml

+10
Original file line numberDiff line numberDiff line change
@@ -68,6 +68,16 @@
6868
<groupId>org.apache.hbase</groupId>
6969
<artifactId>hbase-client</artifactId>
7070
<version>${hbase.version}</version>
71+
<exclusions>
72+
<exclusion>
73+
<groupId>log4j</groupId>
74+
<artifactId>log4j</artifactId>
75+
</exclusion>
76+
<exclusion>
77+
<groupId>org.slf4j</groupId>
78+
<artifactId>slf4j-log4j12</artifactId>
79+
</exclusion>
80+
</exclusions>
7181
</dependency>
7282

7383
<dependency>

pulsar-io/hdfs2/pom.xml

+10
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,16 @@
4949
<groupId>org.apache.hadoop</groupId>
5050
<artifactId>hadoop-client</artifactId>
5151
<version>2.8.5</version>
52+
<exclusions>
53+
<exclusion>
54+
<groupId>log4j</groupId>
55+
<artifactId>log4j</artifactId>
56+
</exclusion>
57+
<exclusion>
58+
<groupId>org.slf4j</groupId>
59+
<artifactId>slf4j-log4j12</artifactId>
60+
</exclusion>
61+
</exclusions>
5262
</dependency>
5363
<dependency>
5464
<groupId>org.apache.commons</groupId>

pulsar-io/hdfs3/pom.xml

+8
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,14 @@
5454
<groupId>jakarta.activation</groupId>
5555
<artifactId>jakarta.activation-api</artifactId>
5656
</exclusion>
57+
<exclusion>
58+
<groupId>log4j</groupId>
59+
<artifactId>log4j</artifactId>
60+
</exclusion>
61+
<exclusion>
62+
<groupId>org.slf4j</groupId>
63+
<artifactId>slf4j-log4j12</artifactId>
64+
</exclusion>
5765
</exclusions>
5866
</dependency>
5967

pulsar-io/kafka-connect-adaptor/pom.xml

+6
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,12 @@
4848
<groupId>org.apache.kafka</groupId>
4949
<artifactId>connect-runtime</artifactId>
5050
<version>${kafka-client.version}</version>
51+
<exclusions>
52+
<exclusion>
53+
<groupId>org.apache.kafka</groupId>
54+
<artifactId>kafka-log4j-appender</artifactId>
55+
</exclusion>
56+
</exclusions>
5157
</dependency>
5258

5359
<dependency>

pulsar-io/kafka/pom.xml

+10
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,16 @@
7070
<groupId>io.confluent</groupId>
7171
<artifactId>kafka-schema-registry</artifactId>
7272
<version>${kafka.confluent.schemaregistryclient.version}</version>
73+
<exclusions>
74+
<exclusion>
75+
<groupId>log4j</groupId>
76+
<artifactId>log4j</artifactId>
77+
</exclusion>
78+
<exclusion>
79+
<groupId>org.slf4j</groupId>
80+
<artifactId>slf4j-log4j12</artifactId>
81+
</exclusion>
82+
</exclusions>
7383
</dependency>
7484

7585
<dependency>

tiered-storage/file-system/pom.xml

+10
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,16 @@
4646
<groupId>org.apache.hadoop</groupId>
4747
<artifactId>hadoop-common</artifactId>
4848
<version>${hdfs-offload-version3}</version>
49+
<exclusions>
50+
<exclusion>
51+
<groupId>log4j</groupId>
52+
<artifactId>log4j</artifactId>
53+
</exclusion>
54+
<exclusion>
55+
<groupId>org.slf4j</groupId>
56+
<artifactId>slf4j-log4j12</artifactId>
57+
</exclusion>
58+
</exclusions>
4959
</dependency>
5060
<dependency>
5161
<groupId>com.google.protobuf</groupId>

0 commit comments

Comments
 (0)