This is an automated email from the ASF dual-hosted git repository.

CalvinKirs pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/doris.git


The following commit(s) were added to refs/heads/master by this push:
     new 152213c21eb [fix](fe) Bump vulnerable FE dependency versions (#68445)
152213c21eb is described below

commit 152213c21eb3e85e8534965279d447da5b0cded9
Author: Calvin Kirs <[email protected]>
AuthorDate: Mon Sep 28 15:03:59 2026 +0800

    [fix](fe) Bump vulnerable FE dependency versions (#68445)
    
    ### What problem does this PR solve?
    
    Issue Number: None
    
    Problem Summary: OWASP dependency-check flagged several FE third-party
    dependencies with known CVEs that have fixed releases available. Bump
    each to its fixed version:
    
    - ranger-plugins-common 2.8.0 -> 2.9.0 (several CRITICAL RCE/injection
    CVEs)
    - netty 4.2.15.Final -> 4.2.17.Final
    - httpclient5 5.6.3 -> 5.6.4
    - hbase 2.6.3 -> 2.6.6
    - jline 3.30.6 -> 3.30.14
    - parquet 1.17.0 -> 1.18.0
    - log4j2 2.25.4 -> 2.25.5, and log4j-1.2-api with it so all log4j
    artifacts stay on one version
    
    Also exclude io.airlift:http-server from trino-main: it pulls in the
    Jetty
    11 server side (jetty-server, jetty-servlet, jetty-security, jetty-jmx,
    http2-server), which Doris never starts. This mirrors the exclusion
    already
    applied on the BE side in be-java-extensions/trino-connector-scanner.
    
    ### Release note
    
    None
    
    ### Check List (For Author)
    
    - Test: Unit Test / Manual test
    - `mvn -pl fe-core -am package` succeeds with 0 Checkstyle violations;
    `mvn dependency:tree` resolves every bumped artifact to its new version
    with no conflicts.
    - The BE plugins that use the same properties (`hadoop-hudi-scanner`,
    `paimon-scanner`, `iceberg-metadata-scanner`, `java-udf`,
    `trino-connector-scanner`) package.
    - Unit tests of `fe-connector-trino` (62),
    `fe-authorization-plugin-ranger-doris` (49) and
    `fe-authorization-plugin-ranger-hive` (22, 1 skipped) pass.
    - Behavior changed: No
    - Does this need documentation: No
---
 fe/pom.xml | 26 ++++++++++++++++++--------
 1 file changed, 18 insertions(+), 8 deletions(-)

diff --git a/fe/pom.xml b/fe/pom.xml
index a04b3ad9838..2dc67714567 100644
--- a/fe/pom.xml
+++ b/fe/pom.xml
@@ -248,7 +248,7 @@ under the License.
     <properties>
         <!-- iceberg 1.9.1 depends avro on 1.12 -->
         <avro.version>1.12.1</avro.version>
-        <parquet.version>1.17.0</parquet.version>
+        <parquet.version>1.18.0</parquet.version>
         <spark.version>3.4.3</spark.version>
         <hudi.version>1.0.2</hudi.version>
         <obs.dependency.scope>compile</obs.dependency.scope>
@@ -306,13 +306,13 @@ under the License.
         <hikaricp.version>6.0.0</hikaricp.version>
         <thrift.version>0.24.0</thrift.version>
         <tomcat-embed.version>9.0.104</tomcat-embed.version>
-        <log4j2.version>2.25.4</log4j2.version>
-        <log4j-1.2.version>2.25.4</log4j-1.2.version>
+        <log4j2.version>2.25.5</log4j2.version>
+        <log4j-1.2.version>2.25.5</log4j-1.2.version>
         <slf4j.version>2.0.17</slf4j.version>
         <metrics-core.version>4.0.2</metrics-core.version>
         <resilience4j.version>2.4.0</resilience4j.version>
         <!-- Keep Netty compatible with Arrow Flight SQL 19 and other 
transitive Netty users. -->
-        <netty-all.version>4.2.15.Final</netty-all.version>
+        <netty-all.version>4.2.17.Final</netty-all.version>
         <!-- OpenTelemetry versions before 1.62.0 allow unbounded allocation 
while parsing W3C
              baggage (CVE-2026-45292); align the complete OpenTelemetry graph 
on the fixed BOM. -->
         <opentelemetry.version>1.62.0</opentelemetry.version>
@@ -384,7 +384,7 @@ under the License.
         <!-- HttpClient 5.5.2 can leak pooled connections on decode errors 
(CVE-2026-64607),
              and HttpCore 5.3.6 is affected by HTTP/1 and HTTP/2 
memory-exhaustion issues
              (CVE-2026-54399 and CVE-2026-54428). Use their fixed maintenance 
releases. -->
-        <httpclient5.version>5.6.3</httpclient5.version>
+        <httpclient5.version>5.6.4</httpclient5.version>
         <httpcore5.version>5.4.3</httpcore5.version>
         <aws-java-sdk.version>1.12.669</aws-java-sdk.version>
         <mariadb-java-client.version>3.0.9</mariadb-java-client.version>
@@ -393,8 +393,8 @@ under the License.
         <re2j.version>1.8</re2j.version>
         
<hadoop.thirdparty.guava.version>1.2.0</hadoop.thirdparty.guava.version>
         
<hadoop.thirdparty.protobuf_3_25.version>1.5.0</hadoop.thirdparty.protobuf_3_25.version>
-        <hbase.version>2.6.3</hbase.version>
-        <jline.version>3.30.6</jline.version>
+        <hbase.version>2.6.6</hbase.version>
+        <jline.version>3.30.14</jline.version>
         <hbase-shaded-gson.version>4.1.7</hbase-shaded-gson.version>
         <antlr4.version>4.13.1</antlr4.version>
         <joda.version>2.8.1</joda.version>
@@ -408,7 +408,7 @@ under the License.
         <orc.version>1.8.4</orc.version>
         <zookeeper.version>3.9.3</zookeeper.version>
         <velocity-engine-core.version>2.4</velocity-engine-core.version>
-        <ranger-plugins-common.version>2.8.0</ranger-plugins-common.version>
+        <ranger-plugins-common.version>2.9.0</ranger-plugins-common.version>
         <!-- Matches the jersey-core the FE already carries; only the Ranger 
plugins ask for it. -->
         <jersey.version>1.19.4</jersey.version>
         <!-- Huawei IAM pulls bcprov-jdk15on 1.69, whose final 1.70 release is 
vulnerable to
@@ -2031,6 +2031,16 @@ under the License.
                         <artifactId>bootstrap</artifactId>
                         <groupId>io.airlift</groupId>
                     </exclusion>
+                    <!-- Same reasoning as 
be-java-extensions/trino-connector-scanner: TrinoBootstrap
+                         only wires 
FeaturesConfig/TypeRegistry/ConnectorServicesProvider for query
+                         planning, never io.airlift.bootstrap.Bootstrap or 
io.airlift.http.server -
+                         FE never starts Trino's own HTTP server. Drops the 
Jetty server side it brings
+                         (jetty-server, jetty-servlet, jetty-security, 
jetty-jmx, http2-server);
+                         http2-client stays, it comes from 
io.airlift:http-client. -->
+                    <exclusion>
+                        <artifactId>http-server</artifactId>
+                        <groupId>io.airlift</groupId>
+                    </exclusion>
                     <exclusion>
                         <artifactId>re2j</artifactId>
                         <groupId>io.trino</groupId>


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to