Skip to content

Commit 9a7269a

Browse files
authored
[fix][sec] Upgrade async-http-client to 2.12.4 to address CVE-2024-53990 (apache#23732)
1 parent 3761dc4 commit 9a7269a

File tree

10 files changed

+14
-21
lines changed

10 files changed

+14
-21
lines changed

distribution/server/src/assemble/LICENSE.bin.txt

+3-3
Original file line numberDiff line numberDiff line change
@@ -389,8 +389,8 @@ The Apache Software License, Version 2.0
389389
* AirCompressor
390390
- io.airlift-aircompressor-0.27.jar
391391
* AsyncHttpClient
392-
- org.asynchttpclient-async-http-client-2.12.1.jar
393-
- org.asynchttpclient-async-http-client-netty-utils-2.12.1.jar
392+
- org.asynchttpclient-async-http-client-2.12.4.jar
393+
- org.asynchttpclient-async-http-client-netty-utils-2.12.4.jar
394394
* Jetty
395395
- org.eclipse.jetty-jetty-client-9.4.56.v20240826.jar
396396
- org.eclipse.jetty-jetty-continuation-9.4.56.v20240826.jar
@@ -570,7 +570,7 @@ Protocol Buffers License
570570

571571
CDDL-1.1 -- ../licenses/LICENSE-CDDL-1.1.txt
572572
* Java Annotations API
573-
- com.sun.activation-javax.activation-1.2.0.jar
573+
- com.sun.activation-jakarta.activation-1.2.2.jar
574574
* Java Servlet API -- javax.servlet-javax.servlet-api-3.1.0.jar
575575
* WebSocket Server API -- javax.websocket-javax.websocket-client-api-1.0.jar
576576
* HK2 - Dependency Injection Kernel

distribution/shell/src/assemble/LICENSE.bin.txt

+3-3
Original file line numberDiff line numberDiff line change
@@ -399,8 +399,8 @@ The Apache Software License, Version 2.0
399399
* AirCompressor
400400
- aircompressor-0.27.jar
401401
* AsyncHttpClient
402-
- async-http-client-2.12.1.jar
403-
- async-http-client-netty-utils-2.12.1.jar
402+
- async-http-client-2.12.4.jar
403+
- async-http-client-netty-utils-2.12.4.jar
404404
* Jetty
405405
- jetty-client-9.4.56.v20240826.jar
406406
- jetty-http-9.4.56.v20240826.jar
@@ -431,7 +431,7 @@ MIT License
431431

432432
CDDL-1.1 -- ../licenses/LICENSE-CDDL-1.1.txt
433433
* Java Annotations API
434-
- javax.activation-1.2.0.jar
434+
- jakarta.activation-1.2.2.jar
435435
* WebSocket Server API -- javax.websocket-client-api-1.0.jar
436436
* HK2 - Dependency Injection Kernel
437437
- hk2-api-2.6.1.jar

pom.xml

+1-8
Original file line numberDiff line numberDiff line change
@@ -215,7 +215,7 @@ flexible messaging model and an intuitive client API.</description>
215215
<prometheus-jmx.version>0.16.1</prometheus-jmx.version>
216216
<confluent.version>6.2.8</confluent.version>
217217
<aircompressor.version>0.27</aircompressor.version>
218-
<asynchttpclient.version>2.12.1</asynchttpclient.version>
218+
<asynchttpclient.version>2.12.4</asynchttpclient.version>
219219
<commons-lang3.version>3.11</commons-lang3.version>
220220
<commons-configuration.version>1.10</commons-configuration.version>
221221
<commons-io.version>2.18.0</commons-io.version>
@@ -233,7 +233,6 @@ flexible messaging model and an intuitive client API.</description>
233233
<lombok.version>1.18.32</lombok.version>
234234
<jakarta.annotation-api.version>1.3.5</jakarta.annotation-api.version>
235235
<jaxb-api>2.3.1</jaxb-api>
236-
<javax.activation.version>1.2.0</javax.activation.version>
237236
<jakarta.activation.version>1.2.2</jakarta.activation.version>
238237
<jakarta.xml.bind.version>2.3.3</jakarta.xml.bind.version>
239238
<jakarta.validation.version>2.0.2</jakarta.validation.version>
@@ -1441,12 +1440,6 @@ flexible messaging model and an intuitive client API.</description>
14411440
<version>${jakarta.xml.bind.version}</version>
14421441
</dependency>
14431442

1444-
<dependency>
1445-
<groupId>com.sun.activation</groupId>
1446-
<artifactId>javax.activation</artifactId>
1447-
<version>${javax.activation.version}</version>
1448-
</dependency>
1449-
14501443
<dependency>
14511444
<groupId>com.sun.activation</groupId>
14521445
<artifactId>jakarta.activation</artifactId>

pulsar-broker/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -458,7 +458,7 @@
458458

459459
<dependency>
460460
<groupId>com.sun.activation</groupId>
461-
<artifactId>javax.activation</artifactId>
461+
<artifactId>jakarta.activation</artifactId>
462462
</dependency>
463463

464464
<dependency>

pulsar-client-admin-shaded/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,7 @@
111111
<include>com.google.re2j:re2j</include>
112112
<include>com.spotify:completable-futures</include>
113113
<include>com.squareup.*:*</include>
114-
<include>com.sun.activation:javax.activation</include>
114+
<include>com.sun.activation:jakarta.activation</include>
115115
<include>com.typesafe.netty:netty-reactive-streams</include>
116116
<include>com.yahoo.datasketches:*</include>
117117
<include>com.yahoo.datasketches:sketches-core</include>

pulsar-client-admin/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@
8787
</dependency>
8888
<dependency>
8989
<groupId>com.sun.activation</groupId>
90-
<artifactId>javax.activation</artifactId>
90+
<artifactId>jakarta.activation</artifactId>
9191
<scope>runtime</scope>
9292
</dependency>
9393

pulsar-client-all/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -152,7 +152,7 @@
152152
<include>com.google.re2j:re2j</include>
153153
<include>com.spotify:completable-futures</include>
154154
<include>com.squareup.*:*</include>
155-
<include>com.sun.activation:javax.activation</include>
155+
<include>com.sun.activation:jakarta.activation</include>
156156
<!-- Avro transitive dependencies -->
157157
<include>com.thoughtworks.paranamer:paranamer</include>
158158
<include>com.typesafe.netty:netty-reactive-streams</include>

pulsar-client-shaded/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -126,7 +126,7 @@
126126
<include>com.google.j2objc:*</include>
127127
<include>com.google.re2j:re2j</include>
128128
<include>com.spotify:completable-futures</include>
129-
<include>com.sun.activation:javax.activation</include>
129+
<include>com.sun.activation:jakarta.activation</include>
130130
<!-- Avro transitive dependencies -->
131131
<include>com.thoughtworks.paranamer:paranamer</include>
132132
<include>com.typesafe.netty:netty-reactive-streams</include>

pulsar-proxy/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -140,7 +140,7 @@
140140

141141
<dependency>
142142
<groupId>com.sun.activation</groupId>
143-
<artifactId>javax.activation</artifactId>
143+
<artifactId>jakarta.activation</artifactId>
144144
</dependency>
145145

146146
<dependency>

tiered-storage/jcloud/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -117,7 +117,7 @@
117117

118118
<dependency>
119119
<groupId>com.sun.activation</groupId>
120-
<artifactId>javax.activation</artifactId>
120+
<artifactId>jakarta.activation</artifactId>
121121
<scope>runtime</scope>
122122
</dependency>
123123

0 commit comments

Comments
 (0)