Skip to content

Updates several dependencies to address CVEs#5914

Merged
dlvenable merged 2 commits intoopensearch-project:mainfrom
dlvenable:cves
Jul 30, 2025
Merged

Updates several dependencies to address CVEs#5914
dlvenable merged 2 commits intoopensearch-project:mainfrom
dlvenable:cves

Conversation

@dlvenable
Copy link
Copy Markdown
Member

Description

Resolves the following CVEs by updating dependencies:

Issues Resolved

N/A

Check List

  • New functionality includes testing.
  • New functionality has a documentation issue. Please link to it in this PR.
    • New functionality has javadoc added
  • Commits are signed with a real name per the DCO

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

* CVE-2025-46762 - Parquet 1.15.2
* CVE-2025-48734 - commons-beanutils 1.11.0 and Checkstyle 10.26.1
* CVE-2024-57699 - json-smart 2.5.2
* CVE-2025-24970 - Netty 4.1.123
* CVE-2025-27817 - Apache Kafka 3.9.1 and Confluent Kafka 7.9.1

Signed-off-by: David Venable <dlv@amazon.com>
Signed-off-by: David Venable <dlv@amazon.com>
@dlvenable dlvenable merged commit c8f66fa into opensearch-project:main Jul 30, 2025
75 of 80 checks passed
opensearch-trigger-bot bot pushed a commit that referenced this pull request Jul 30, 2025
Updates several dependencies to address CVEs

* CVE-2025-46762 - Parquet 1.15.2
* CVE-2025-48734 - commons-beanutils 1.11.0 and Checkstyle 10.26.1
* CVE-2024-57699 - json-smart 2.5.2
* CVE-2025-24970 - Netty 4.1.123
* CVE-2025-27817 - Apache Kafka 3.9.1 and Confluent Kafka 7.9.1

Also, removes some broken code related to the kafka-client in unused Kafka tests.

Signed-off-by: David Venable <dlv@amazon.com>
(cherry picked from commit c8f66fa)
dlvenable added a commit that referenced this pull request Jul 30, 2025
Updates several dependencies to address CVEs

* CVE-2025-46762 - Parquet 1.15.2
* CVE-2025-48734 - commons-beanutils 1.11.0 and Checkstyle 10.26.1
* CVE-2024-57699 - json-smart 2.5.2
* CVE-2025-24970 - Netty 4.1.123
* CVE-2025-27817 - Apache Kafka 3.9.1 and Confluent Kafka 7.9.1

Also, removes some broken code related to the kafka-client in unused Kafka tests.


(cherry picked from commit c8f66fa)

Signed-off-by: David Venable <dlv@amazon.com>
Co-authored-by: David Venable <dlv@amazon.com>
@dlvenable dlvenable deleted the cves branch July 31, 2025 15:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants