This is an automated email from the ASF dual-hosted git repository.
yiguolei pushed a commit to branch branch-4.1
in repository https://gitbox.apache.org/repos/asf/doris.git
The following commit(s) were added to refs/heads/branch-4.1 by this push:
new c2680189917 branch-4.1: [fix](fe) Bump vulnerable FE dependency
versions (#68557)
c2680189917 is described below
commit c2680189917bea878034195f72e3e9e8b521e317
Author: Calvin Kirs <[email protected]>
AuthorDate: Tue Sep 29 09:32:45 2026 +0800
branch-4.1: [fix](fe) Bump vulnerable FE dependency versions (#68557)
https://github.com/apache/doris/pull/68445
---
fe/pom.xml | 26 ++++++++++++++++++--------
1 file changed, 18 insertions(+), 8 deletions(-)
diff --git a/fe/pom.xml b/fe/pom.xml
index 41c040cc869..3322689eaae 100644
--- a/fe/pom.xml
+++ b/fe/pom.xml
@@ -234,7 +234,7 @@ under the License.
<doris.hive.catalog.shade.version>3.1.3</doris.hive.catalog.shade.version>
<!-- iceberg 1.9.1 depends avro on 1.12 -->
<avro.version>1.12.1</avro.version>
- <parquet.version>1.17.0</parquet.version>
+ <parquet.version>1.18.0</parquet.version>
<spark.version>3.4.3</spark.version>
<hudi.version>1.0.2</hudi.version>
<obs.dependency.scope>compile</obs.dependency.scope>
@@ -291,14 +291,14 @@ under the License.
<hikaricp.version>6.0.0</hikaricp.version>
<thrift.version>0.24.0</thrift.version>
<tomcat-embed.version>9.0.104</tomcat-embed.version>
- <log4j2.version>2.25.4</log4j2.version>
- <log4j-1.2.version>2.25.4</log4j-1.2.version>
+ <log4j2.version>2.25.5</log4j2.version>
+ <log4j-1.2.version>2.25.5</log4j-1.2.version>
<mqtt.version>1.2.5</mqtt.version>
<slf4j.version>2.0.17</slf4j.version>
<metrics-core.version>4.0.2</metrics-core.version>
<resilience4j.version>2.4.0</resilience4j.version>
<!-- Keep Netty compatible with Arrow Flight SQL 19 and other
transitive Netty users. -->
- <netty-all.version>4.2.15.Final</netty-all.version>
+ <netty-all.version>4.2.17.Final</netty-all.version>
<!-- OpenTelemetry versions before 1.62.0 allow unbounded allocation
while parsing W3C
baggage (CVE-2026-45292); align the complete OpenTelemetry graph
on the fixed BOM. -->
<opentelemetry.version>1.62.0</opentelemetry.version>
@@ -373,7 +373,7 @@ under the License.
<!-- HttpClient 5.5.2 can leak pooled connections on decode errors
(CVE-2026-64607),
and HttpCore 5.3.6 is affected by HTTP/1 and HTTP/2
memory-exhaustion issues
(CVE-2026-54399 and CVE-2026-54428). Use their fixed maintenance
releases. -->
- <httpclient5.version>5.6.3</httpclient5.version>
+ <httpclient5.version>5.6.4</httpclient5.version>
<httpcore5.version>5.4.3</httpcore5.version>
<aws-java-sdk.version>1.12.669</aws-java-sdk.version>
<mariadb-java-client.version>3.0.9</mariadb-java-client.version>
@@ -382,8 +382,8 @@ under the License.
<re2j.version>1.8</re2j.version>
<hadoop.thirdparty.guava.version>1.2.0</hadoop.thirdparty.guava.version>
<hadoop.thirdparty.protobuf_3_25.version>1.5.0</hadoop.thirdparty.protobuf_3_25.version>
- <hbase.version>2.6.3</hbase.version>
- <jline.version>3.30.6</jline.version>
+ <hbase.version>2.6.6</hbase.version>
+ <jline.version>3.30.14</jline.version>
<hbase-shaded-gson.version>4.1.7</hbase-shaded-gson.version>
<antlr4.version>4.13.1</antlr4.version>
<joda.version>2.8.1</joda.version>
@@ -397,7 +397,7 @@ under the License.
<orc.version>1.8.4</orc.version>
<zookeeper.version>3.9.3</zookeeper.version>
<velocity-engine-core.version>2.4</velocity-engine-core.version>
- <ranger-plugins-common.version>2.8.0</ranger-plugins-common.version>
+ <ranger-plugins-common.version>2.9.0</ranger-plugins-common.version>
<!-- Huawei IAM pulls bcprov-jdk15on 1.69, whose final 1.70 release is
vulnerable to
CVE-2023-33202. Use the compatible jdk18on line at 1.84, which
also fixes
CVE-2025-14813, CVE-2026-0636, CVE-2026-3505, CVE-2026-5588, and
CVE-2026-5598. -->
@@ -1898,6 +1898,16 @@ under the License.
<artifactId>bootstrap</artifactId>
<groupId>io.airlift</groupId>
</exclusion>
+ <!-- trino-main is used to load Trino connector plugins
and plan through them
+ (fe-common and fe-core datasource/trinoconnector, BE
trino-connector-scanner);
+ none of them starts Trino's own HTTP server
(io.airlift.http.server). Drops
+ the Jetty server side it brings (jetty-servlet,
http2-server, jetty-jmx, and
+ jetty-server/jetty-security where nothing else brings
them); http2-client
+ stays, it comes from io.airlift:http-client. -->
+ <exclusion>
+ <artifactId>http-server</artifactId>
+ <groupId>io.airlift</groupId>
+ </exclusion>
<exclusion>
<artifactId>re2j</artifactId>
<groupId>io.trino</groupId>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]