From eb4517da34fe5635ca094d61a00ac688382b2d6b Mon Sep 17 00:00:00 2001 From: Sarat Vemulapalli Date: Mon, 9 Jan 2023 22:58:52 -0800 Subject: [PATCH 1/2] Upgrading Jettison due to CVE Signed-off-by: Sarat Vemulapalli --- buildSrc/version.properties | 2 +- .../discovery-azure-classic/licenses/jettison-1.5.1.jar.sha1 | 1 - .../discovery-azure-classic/licenses/jettison-1.5.3.jar.sha1 | 1 + 3 files changed, 2 insertions(+), 2 deletions(-) delete mode 100644 plugins/discovery-azure-classic/licenses/jettison-1.5.1.jar.sha1 create mode 100644 plugins/discovery-azure-classic/licenses/jettison-1.5.3.jar.sha1 diff --git a/buildSrc/version.properties b/buildSrc/version.properties index 18db45a2c00c0..3b61c4a37327a 100644 --- a/buildSrc/version.properties +++ b/buildSrc/version.properties @@ -17,7 +17,7 @@ supercsv = 2.4.0 log4j = 2.17.1 slf4j = 1.7.36 asm = 9.4 -jettison = 1.5.1 +jettison = 1.5.3 woodstox = 6.4.0 kotlin = 1.7.10 antlr4 = 4.11.1 diff --git a/plugins/discovery-azure-classic/licenses/jettison-1.5.1.jar.sha1 b/plugins/discovery-azure-classic/licenses/jettison-1.5.1.jar.sha1 deleted file mode 100644 index 29227ed427953..0000000000000 --- a/plugins/discovery-azure-classic/licenses/jettison-1.5.1.jar.sha1 +++ /dev/null @@ -1 +0,0 @@ -d8918f348f234f5046bd39ea1ed9fc91deac402f \ No newline at end of file diff --git a/plugins/discovery-azure-classic/licenses/jettison-1.5.3.jar.sha1 b/plugins/discovery-azure-classic/licenses/jettison-1.5.3.jar.sha1 new file mode 100644 index 0000000000000..afd13439e739c --- /dev/null +++ b/plugins/discovery-azure-classic/licenses/jettison-1.5.3.jar.sha1 @@ -0,0 +1 @@ +964d35bbdecbbc33cf2f2044e8a1648d9f6f1474 \ No newline at end of file From b00d88b7821cf0d2cf5e888929310dfde6a7738e Mon Sep 17 00:00:00 2001 From: Sarat Vemulapalli Date: Mon, 9 Jan 2023 23:03:39 -0800 Subject: [PATCH 2/2] Updated Changelog Signed-off-by: Sarat Vemulapalli --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 2701cb9598ac1..5874d76c8e612 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -29,7 +29,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), ### Dependencies - Bumps `log4j-core` from 2.18.0 to 2.19.0 - Bumps `reactor-netty-http` from 1.0.18 to 1.0.23 -- Bumps `jettison` from 1.5.0 to 1.5.1 +- Bumps `jettison` from 1.5.0 to 1.5.3 - Bumps `forbiddenapis` from 3.3 to 3.4 - Bumps `gson` from 2.9.0 to 2.10 - Bumps `avro` from 1.11.0 to 1.11.1