Nikola Stanisavljevic created FLINK-40206:
---------------------------------------------
Summary: Upgrade pulsar client to latest patch version to address
critical vulnerabilities
Key: FLINK-40206
URL: https://issues.apache.org/jira/browse/FLINK-40206
Project: Flink
Issue Type: Bug
Components: Connectors / Pulsar
Reporter: Nikola Stanisavljevic
pulsar-client-all dependency ships shaded copies of libraries which have two
Critical-severity CVEs:
* [CVE-2023-39410|https://github.com/advisories/GHSA-r7pg-v2c8-mfg3]- avro
* [CVE-2024-53990|https://github.com/advisories/GHSA-mfj5-cf8g-g2fv]-
async-http-client
Simply forcing resolution to latest patch version of pulsar-client-all does not
work, because connector is using
_PulsarClientImpl.getPartitionedTopicMetadata(String)_ directly instead of
going through the public PulsarClient. Pathed version does not have this method
signature in {_}PulsarClientImpl{_}, thus connector raises
_java.lang.NoSuchMethodError_
*Solution:*
* Use public interface of _PulsarClient_ instead of _PulsarClientImpl_
* Update pulsar-client-all to latest patch version
--
This message was sent by Atlassian Jira
(v8.20.10#820010)