rcprcp commented on issue #39288:
URL: https://github.com/apache/arrow/issues/39288#issuecomment-1863331864

   Hi @danepitkin  - thanks for picking up this issue so quickly.  
   
   Your help with this is greatly appreciated.   🥇 
   
   We realize now that there is one other important CVE that's included in 
flight-sql-jdbc-driver and we also need this one resolved as well:
   
[https://nvd.nist.gov/vuln/detail/CVE-2022-36364](https://nvd.nist.gov/vuln/detail/CVE-2022-36364)
   
   This vulnerability is introduced by the reference to Avatica v 1.18.0.  In 
Avatica version 1.22.0 and above, this issue is resolved. 
   
   In  
[https://mvnrepository.com/artifact/org.apache.calcite.avatica/avatica-core](https://mvnrepository.com/artifact/org.apache.calcite.avatica/avatica-core)
   
   Is it possible to also upgrade the Avatica dependency in the 
flight-sql-jdbc-driver?
   
   Thank you for your help.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to