Skip to content

Commit 7d20a03

Browse files
authored
Reverted pulsar version to 3.2.2 while fixing avro vulnerability (#164)
1 parent 7b25426 commit 7d20a03

File tree

3 files changed

+42
-2
lines changed

3 files changed

+42
-2
lines changed

examples/spring/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@
4646
<dependency>
4747
<!-- DataStax Apache Pulsar JMS Client -->
4848
<groupId>com.datastax.oss</groupId>
49-
<artifactId>pulsar-jms-all</artifactId>
49+
<artifactId>pulsar-jms</artifactId>
5050
<version>${project.version}</version>
5151
</dependency>
5252
<dependency>

pom.xml

+21-1
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@
5555
<maven.compiler.release>17</maven.compiler.release>
5656
<jms.version>3.0.0</jms.version>
5757
<pulsar.groupId>org.apache.pulsar</pulsar.groupId>
58-
<pulsar.version>3.3.2</pulsar.version>
58+
<pulsar.version>3.2.2</pulsar.version>
5959
<activemq.version>6.0.0</activemq.version>
6060
<hawtbuf.version>1.11</hawtbuf.version>
6161
<curator.version>5.1.0</curator.version>
@@ -130,6 +130,26 @@
130130
<groupId>${pulsar.groupId}</groupId>
131131
<artifactId>pulsar-client-original</artifactId>
132132
<version>${pulsar.version}</version>
133+
<exclusions>
134+
<exclusion>
135+
<groupId>org.apache.avro</groupId>
136+
<artifactId>avro</artifactId>
137+
</exclusion>
138+
<exclusion>
139+
<groupId>org.apache.avro</groupId>
140+
<artifactId>avro-protobuf</artifactId>
141+
</exclusion>
142+
</exclusions>
143+
</dependency>
144+
<dependency>
145+
<groupId>org.apache.avro</groupId>
146+
<artifactId>avro</artifactId>
147+
<version>1.11.4</version>
148+
</dependency>
149+
<dependency>
150+
<groupId>org.apache.avro</groupId>
151+
<artifactId>avro-protobuf</artifactId>
152+
<version>1.11.4</version>
133153
</dependency>
134154
<dependency>
135155
<groupId>${pulsar.groupId}</groupId>

pulsar-jms/pom.xml

+20
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,26 @@
5454
<dependency>
5555
<groupId>${pulsar.groupId}</groupId>
5656
<artifactId>pulsar-client-original</artifactId>
57+
<exclusions>
58+
<exclusion>
59+
<groupId>org.apache.avro</groupId>
60+
<artifactId>avro</artifactId>
61+
</exclusion>
62+
<exclusion>
63+
<groupId>org.apache.avro</groupId>
64+
<artifactId>avro-protobuf</artifactId>
65+
</exclusion>
66+
</exclusions>
67+
</dependency>
68+
<dependency>
69+
<groupId>org.apache.avro</groupId>
70+
<artifactId>avro</artifactId>
71+
<version>1.11.4</version>
72+
</dependency>
73+
<dependency>
74+
<groupId>org.apache.avro</groupId>
75+
<artifactId>avro-protobuf</artifactId>
76+
<version>1.11.4</version>
5777
</dependency>
5878
<dependency>
5979
<groupId>${pulsar.groupId}</groupId>

0 commit comments

Comments
 (0)