Databricks-jdbc and vulnerabilities CVE-2021-36090 CVE-2023-6378 CVE-2023-6481
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-06-2024 11:18 AM
The latest version of Databricks-jdbc available through Maven (2.6.36) now has these three vulnerabilities:
https://www.cve.org/CVERecord?id=CVE-2021-36090
https://www.cve.org/CVERecord?id=CVE-2023-6378
https://www.cve.org/CVERecord?id=CVE-2023-6481
All due to depending on and including in the jar the older versions of the below jar dependencies
org.apache.commons:commons-compress@1.20
ch.qos.logback:logback-classic@1.2.3
ch.qos.logback:logback-core@1.2.3
Is there a possibility to have a new updated version of Databricks-jdbc that uses the latest of these dependent jars?
org.apache.commons:commons-compress@1.25
ch.qos.logback:logback-classic@1.2.13 or @1.4.14
ch.qos.logback:logback-core@1.2.13 or @1.4.14

