Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-32441

Upgrade Avro from 1.9.2 to 1.11.3

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 2021.0
    • Fix Version/s: 2021.54
    • Component/s: Security
    • Release Notes Summary:
      Make sure custom Avro Schemas are registered.
    • Backlog priority:
      900
    • Upgrade notes:
      Hide

      Avro library has been upgraded for security reason. The new version changes the Avro Schema definition and its fingerprints. Nuxeo is taking care of contributing old and new schemas to be backward compatible.
      If you are defining custom Avro Schemas, they must be registered to ensure the backward compatibility.

      Show
      Avro library has been upgraded for security reason. The new version changes the Avro Schema definition and its fingerprints. Nuxeo is taking care of contributing old and new schemas to be backward compatible. If you are defining custom Avro Schemas, they must be registered to ensure the backward compatibility.
    • Sprint:
      nxplatform #112
    • Story Points:
      5

      Description

      In order to fix CVE-2023-39410 we need to upgrade avro from 1.9.2 (or 1.11.1 for LTS 2023) to 1.11.3

      https://github.com/advisories/GHSA-rhrv-645h-fjfh

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                4 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: