Skip to content

[Task]: Google Cloud Platform Expansion Service contains CVE-2024-47561 #34968

Description

@pineapple-pokopo

What needs to happen?

The latest version of the Java IO Google Cloud Platform Expansion Service contains an outdated version of Avro (1.11.3). It should be upgraded to 1.11.4 to fix CVE-2024-47561.

There is a related issue #33144 and PR #32770, but even the latest build on master still contains Avro 1.11.3: https://develocity.apache.org/s/htp5xqpbxo64m/dependencies?focusedDependency=WzE5LDQsMjE3MyxbMTksNCxbMTMxMSwyMTczXV1d&toggled=W1sxOV0sWzE5LDRdLFsxOSw0LFsxMzExXV1d

Issue Priority

Priority: 2 (default / most normal work should be filed as P2)

Issue Components

  • Component: Python SDK
  • Component: Java SDK
  • Component: Go SDK
  • Component: Typescript SDK
  • Component: IO connector
  • Component: Beam YAML
  • Component: Beam examples
  • Component: Beam playground
  • Component: Beam katas
  • Component: Website
  • Component: Infrastructure
  • Component: Spark Runner
  • Component: Flink Runner
  • Component: Samza Runner
  • Component: Twister2 Runner
  • Component: Hazelcast Jet Runner
  • Component: Google Cloud Dataflow Runner
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions