Uploaded image for project: 'Debezium'
  1. Debezium
  2. DBZ-8864

Upgrade RocketMQ version from 5.1.4 to 5.2.0

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Major Major
    • 3.2.0.Alpha1
    • None
    • debezium-server
    • None
    • False
    • Hide

      None

      Show
      None
    • False

      RocketMQ version 5.1.4 includes a dependency on com.squareup.okio:okio-jvm, which has a known security vulnerability: CVE-2023-3635. This issue is resolved in RocketMQ version 5.2.0, where okio-jvm is upgraded to version 3.4.0. To address the vulnerability, we should update the RocketMQ dependency in Debezium to version 5.2.0. According to the 5.2.0 release notes, there are no breaking changes, so the upgrade should be safe.

              Unassigned Unassigned
              petar.kostov Petar Kostov (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: