|
| 1 | +Fix CVE-2023-34455 |
| 2 | + |
| 3 | +See https://github.com/stackabletech/vulnerabilities/issues/558 |
| 4 | + |
| 5 | +diff --git a/phoenix-core-client/pom.xml b/phoenix-core-client/pom.xml |
| 6 | +index f711b0f6f..3cfbffef9 100644 |
| 7 | +--- a/phoenix-core-client/pom.xml |
| 8 | ++++ b/phoenix-core-client/pom.xml |
| 9 | +@@ -230,6 +230,12 @@ |
| 10 | + <groupId>org.apache.hadoop</groupId> |
| 11 | + <artifactId>hadoop-auth</artifactId> |
| 12 | + </dependency> |
| 13 | ++ <!-- Fix CVE-2023-34455 --> |
| 14 | ++ <dependency> |
| 15 | ++ <groupId>org.xerial.snappy</groupId> |
| 16 | ++ <artifactId>snappy-java</artifactId> |
| 17 | ++ <version>1.1.10.4</version> |
| 18 | ++ </dependency> |
| 19 | + |
| 20 | + <!-- HBase dependencies --> |
| 21 | + <dependency> |
| 22 | +diff --git a/phoenix-core-server/pom.xml b/phoenix-core-server/pom.xml |
| 23 | +index d5032ece2..e47fb0837 100644 |
| 24 | +--- a/phoenix-core-server/pom.xml |
| 25 | ++++ b/phoenix-core-server/pom.xml |
| 26 | +@@ -59,6 +59,12 @@ |
| 27 | + <groupId>org.apache.hadoop</groupId> |
| 28 | + <artifactId>hadoop-mapreduce-client-core</artifactId> |
| 29 | + </dependency> |
| 30 | ++ <!-- Fix CVE-2023-34455 --> |
| 31 | ++ <dependency> |
| 32 | ++ <groupId>org.xerial.snappy</groupId> |
| 33 | ++ <artifactId>snappy-java</artifactId> |
| 34 | ++ <version>1.1.10.4</version> |
| 35 | ++ </dependency> |
| 36 | + |
| 37 | + <!-- HBase dependencies --> |
| 38 | + <dependency> |
| 39 | +@@ -192,4 +198,4 @@ |
| 40 | + </plugin> |
| 41 | + </plugins> |
| 42 | + </build> |
| 43 | +-</project> |
| 44 | +\ No newline at end of file |
| 45 | ++</project> |
| 46 | +diff --git a/phoenix-pherf/pom.xml b/phoenix-pherf/pom.xml |
| 47 | +index c03fff9a1..cdcce2f98 100644 |
| 48 | +--- a/phoenix-pherf/pom.xml |
| 49 | ++++ b/phoenix-pherf/pom.xml |
| 50 | +@@ -159,6 +159,12 @@ |
| 51 | + <groupId>org.apache.hbase</groupId> |
| 52 | + <artifactId>hbase-server</artifactId> |
| 53 | + </dependency> |
| 54 | ++ <!-- Fix CVE-2023-34455 --> |
| 55 | ++ <dependency> |
| 56 | ++ <groupId>org.xerial.snappy</groupId> |
| 57 | ++ <artifactId>snappy-java</artifactId> |
| 58 | ++ <version>1.1.10.4</version> |
| 59 | ++ </dependency> |
| 60 | + |
| 61 | + <!-- Test Dependencies --> |
| 62 | + <dependency> |
| 63 | +diff --git a/phoenix-tracing-webapp/pom.xml b/phoenix-tracing-webapp/pom.xml |
| 64 | +index d2d1549ef..c8054159e 100755 |
| 65 | +--- a/phoenix-tracing-webapp/pom.xml |
| 66 | ++++ b/phoenix-tracing-webapp/pom.xml |
| 67 | +@@ -89,6 +89,12 @@ |
| 68 | + <groupId>org.apache.hbase</groupId> |
| 69 | + <artifactId>hbase-common</artifactId> |
| 70 | + </dependency> |
| 71 | ++ <!-- Fix CVE-2023-34455 --> |
| 72 | ++ <dependency> |
| 73 | ++ <groupId>org.xerial.snappy</groupId> |
| 74 | ++ <artifactId>snappy-java</artifactId> |
| 75 | ++ <version>1.1.10.4</version> |
| 76 | ++ </dependency> |
| 77 | + </dependencies> |
| 78 | + |
| 79 | + <build> |
| 80 | +diff --git a/pom.xml b/pom.xml |
| 81 | +index 4abcb5a28..21dcf71ad 100644 |
| 82 | +--- a/pom.xml |
| 83 | ++++ b/pom.xml |
| 84 | +@@ -850,6 +850,13 @@ |
| 85 | + </exclusion> |
| 86 | + </exclusions> |
| 87 | + </dependency> |
| 88 | ++ <!-- Fix CVE-2023-34455 --> |
| 89 | ++ <dependency> |
| 90 | ++ <groupId>org.xerial.snappy</groupId> |
| 91 | ++ <artifactId>snappy-java</artifactId> |
| 92 | ++ <version>1.1.10.4</version> |
| 93 | ++ </dependency> |
| 94 | ++ |
| 95 | + <dependency> |
| 96 | + <groupId>org.apache.hadoop</groupId> |
| 97 | + <artifactId>hadoop-common</artifactId> |
0 commit comments