apache / parquet-java

Apache Parquet Java
https://parquet.apache.org/
Apache License 2.0
2.48k stars 1.37k forks source link

Bump io.airlift:aircompressor to 0.27 in parquet-hadoop #2913

Closed asfimport closed 3 weeks ago

asfimport commented 1 month ago

A high severity out-of-bound R/W vulnerability was found in aircompressor and was fixed in version 0.27. parquet-hadoop should be updated from 0.26 to use the new version.

https://nvd.nist.gov/vuln/detail/CVE-2024-36114

 

Pull request: https://github.com/apache/parquet-java/pull/1363

Reporter: Utku Aydin

PRs and other links:

Note: This issue was originally created as PARQUET-2487. Please see the migration documentation for further details.