From 04c1102929b2253ad74272b7d5d8f9a01914620c Mon Sep 17 00:00:00 2001 From: Indhumathi Date: Thu, 6 Feb 2025 18:27:09 +0530 Subject: [PATCH] HIVE-28704: Upgrade pac4j core and opensamlv3 and exclude Javax.json to fix CVE-2023-7272 (#5620) (Indhumathi Muthumurugesh, reviewed by Shohei Okumiya) --- pom.xml | 6 +++++- service/pom.xml | 4 ++++ standalone-metastore/pom.xml | 2 +- 3 files changed, 10 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index f16874246174..80eafeb19dc7 100644 --- a/pom.xml +++ b/pom.xml @@ -190,7 +190,7 @@ 4.1.116.Final 3.10.5.Final - 4.5.5 + 4.5.8 2.8 1.14.4 0.16.0 @@ -880,6 +880,10 @@ org.javassist javassist + + org.glassfish + javax.json + diff --git a/service/pom.xml b/service/pom.xml index 307050618aec..ec4fc6eea606 100644 --- a/service/pom.xml +++ b/service/pom.xml @@ -190,6 +190,10 @@ org.bouncycastle bcprov-jdk15on + + org.glassfish + javax.json + diff --git a/standalone-metastore/pom.xml b/standalone-metastore/pom.xml index 81e80833a8bf..7389058e8678 100644 --- a/standalone-metastore/pom.xml +++ b/standalone-metastore/pom.xml @@ -108,7 +108,7 @@ 1.7.30 4.4.13 4.5.13 - 4.5.5 + 4.5.8 9.37.3 9.4.45.v20220203 1.3.2