Skip to content

Commit

Permalink
[improve] Upgrade wildfly-eytron (used by debezium) to fix CVE-2022-3143
Browse files Browse the repository at this point in the history
 (apache#19333)

(cherry picked from commit 71dafe8)
  • Loading branch information
dlg99 authored and ANNAVAR.SATISH committed Mar 6, 2023
1 parent e29940b commit bd84221
Show file tree
Hide file tree
Showing 2 changed files with 43 additions and 1 deletion.
4 changes: 3 additions & 1 deletion pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -160,6 +160,8 @@ flexible messaging model and an intuitive client API.</description>
<scala-library.version>2.13.10</scala-library.version>
<debezium.version>1.7.1.Final</debezium.version>
<debezium.postgresql.version>42.4.1</debezium.postgresql.version>
<!-- Override version that brings CVE-2022-3143 with debezium -->
<wildfly-elytron.version>1.15.16.Final</wildfly-elytron.version>
<jsonwebtoken.version>0.11.1</jsonwebtoken.version>
<opencensus.version>0.28.0</opencensus.version>
<hbase.version>2.3.0</hbase.version>
Expand Down Expand Up @@ -255,7 +257,7 @@ flexible messaging model and an intuitive client API.</description>
<errorprone-slf4j.version>0.1.4</errorprone-slf4j.version>
<j2objc-annotations.version>1.3</j2objc-annotations.version>
<lightproto-maven-plugin.version>0.4</lightproto-maven-plugin.version>
<dependency-check-maven.version>7.4.4</dependency-check-maven.version>
<dependency-check-maven.version>8.0.1</dependency-check-maven.version>
<roaringbitmap.version>0.9.15</roaringbitmap.version>

<!-- Used to configure rename.netty.native. Libs -->
Expand Down
40 changes: 40 additions & 0 deletions pulsar-io/debezium/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,46 @@
<artifactId>pulsar-io-debezium</artifactId>
<name>Pulsar IO :: Debezium</name>

<dependencyManagement>
<dependencies>
<dependency>
<groupId>org.wildfly.security</groupId>
<artifactId>wildfly-elytron-sasl-digest</artifactId>
<version>${wildfly-elytron.version}</version>
</dependency>
<dependency>
<groupId>org.wildfly.security</groupId>
<artifactId>wildfly-elytron-sasl-external</artifactId>
<version>${wildfly-elytron.version}</version>
</dependency>
<dependency>
<groupId>org.wildfly.security</groupId>
<artifactId>wildfly-elytron-sasl-gs2</artifactId>
<version>${wildfly-elytron.version}</version>
</dependency>
<dependency>
<groupId>org.wildfly.security</groupId>
<artifactId>wildfly-elytron-sasl-oauth2</artifactId>
<version>${wildfly-elytron.version}</version>
</dependency>
<dependency>
<groupId>org.wildfly.security</groupId>
<artifactId>wildfly-elytron-sasl-plain</artifactId>
<version>${wildfly-elytron.version}</version>
</dependency>
<dependency>
<groupId>org.wildfly.security</groupId>
<artifactId>wildfly-elytron-sasl-scram</artifactId>
<version>${wildfly-elytron.version}</version>
</dependency>
<dependency>
<groupId>org.wildfly.security</groupId>
<artifactId>wildfly-elytron-password-impl</artifactId>
<version>${wildfly-elytron.version}</version>
</dependency>
</dependencies>
</dependencyManagement>

<modules>
<module>core</module>
<module>mysql</module>
Expand Down

0 comments on commit bd84221

Please sign in to comment.