exasol / spark-connector

A connector for Apache Spark to access Exasol
Apache License 2.0
12 stars 7 forks source link

Fix CVE-2024-36114 in io.airlift:aircompressor:jar:0.21:provided #225

Closed kaklakariada closed 5 months ago

kaklakariada commented 5 months ago
Error:  Failed to execute goal org.sonatype.ossindex.maven:ossindex-maven-plugin:3.2.0:audit (default-cli) on project spark-connector-jdbc_2.13: Detected 1 vulnerable components:
Error:    io.airlift:aircompressor:jar:0.21:provided; https://ossindex.sonatype.org/component/pkg:maven/io.airlift/aircompressor@0.21?utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error:      * [CVE-2024-36114] CWE-125: Out-of-bounds Read (8.6); https://ossindex.sonatype.org/vulnerability/CVE-2024-36114?component-type=maven&component-name=io.airlift%2Faircompressor&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1