[ 
https://issues.apache.org/jira/browse/HBASE-28127?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Duo Zhang updated HBASE-28127:
------------------------------
    Fix Version/s: 2.6.0
                   2.4.18
                   2.5.6
                   3.0.0-beta-1

> Upgrade avro version to 1.11.3
> ------------------------------
>
>                 Key: HBASE-28127
>                 URL: https://issues.apache.org/jira/browse/HBASE-28127
>             Project: HBase
>          Issue Type: Task
>          Components: dependencies, security
>            Reporter: Duo Zhang
>            Assignee: Duo Zhang
>            Priority: Major
>             Fix For: 2.6.0, 2.4.18, 2.5.6, 3.0.0-beta-1
>
>
> Dependabot has an alert about https://nvd.nist.gov/vuln/detail/CVE-2023-39410
> But it says that it can not upgrade the dependencies automatically.
> Let's update it manually.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to