Code name: Fix Vulnerabilities CVE-2023-44981 and CVE-2023-46120
This release fixes vulnerabilities
- CVE-2023-42503 by overriding version
3.6.3
of transitive dependencyorg.apache.zookeeper:zookeeper
viaorg.apache.hadoop:hadoop-common
- CVE-2023-46120 by excluding transitive dependency
com.rabbitmq:amqp-client
viaorg.alluxio:alluxio-core-client-hdfs
- #281: Fixed vulnerabilities CVE-2023-44981 and CVE-2023-46120
- Updated
com.exasol:parquet-io-java:2.0.5
to2.0.6
- Updated
com.google.guava:guava:32.1.2-jre
to32.1.3-jre
- Updated
io.dropwizard.metrics:metrics-core:4.2.20
to4.2.21
- Updated
io.grpc:grpc-netty:1.56.1
to1.59.0
- Updated
io.netty:netty-handler:4.1.99.Final
to4.1.100.Final
- Updated
org.apache.logging.log4j:log4j-1.2-api:2.20.0
to2.21.1
- Updated
org.apache.logging.log4j:log4j-api:2.20.0
to2.21.1
- Updated
org.apache.logging.log4j:log4j-core:2.20.0
to2.21.1
- Added
org.apache.zookeeper:zookeeper:3.9.1
- Updated
com.exasol:extension-manager-integration-test-java:0.5.1
to0.5.4
- Updated
com.exasol:error-code-crawler-maven-plugin:1.3.0
to1.3.1
- Updated
com.exasol:project-keeper-maven-plugin:2.9.12
to2.9.14
- Updated
org.apache.maven.plugins:maven-enforcer-plugin:3.4.0
to3.4.1
- Updated
org.codehaus.mojo:versions-maven-plugin:2.16.0
to2.16.1
- Updated
org.jacoco:jacoco-maven-plugin:0.8.10
to0.8.11
- Updated
org.sonarsource.scanner.maven:sonar-maven-plugin:3.9.1.2184
to3.10.0.2594