[ 
https://issues.apache.org/jira/browse/CALCITE-5232?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Julian Hyde updated CALCITE-5232:
---------------------------------
    Fix Version/s: 1.32.0
                   avatica-1.23.0

> Upgrade protobuf-java from 3.17.1 to 3.21.5
> -------------------------------------------
>
>                 Key: CALCITE-5232
>                 URL: https://issues.apache.org/jira/browse/CALCITE-5232
>             Project: Calcite
>          Issue Type: Bug
>          Components: avatica, core
>    Affects Versions: 1.31.0, avatica-1.22.0
>            Reporter: Julian Hyde
>            Assignee: Julian Hyde
>            Priority: Major
>             Fix For: 1.32.0, avatica-1.23.0
>
>
> Upgrade protobuf-java in Calcite and Avatica.
> Some scanning tools say that the current version, 3.17.1, is affected by 
> [CVE-2021-22569|https://nvd.nist.gov/vuln/detail/CVE-2021-22569]. It is not, 
> but this upgrade makes those warnings go away.
> As for CALCITE-4626, we plan to upgrade both Avatica and Calcite, to keep 
> them on the same protobuf-java version.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to