-
Task
-
Resolution: Done
-
Major
-
None
-
None
-
False
-
-
False
RocketMQ version 5.1.4 includes a dependency on com.squareup.okio:okio-jvm, which has a known security vulnerability: CVE-2023-3635. This issue is resolved in RocketMQ version 5.2.0, where okio-jvm is upgraded to version 3.4.0. To address the vulnerability, we should update the RocketMQ dependency in Debezium to version 5.2.0. According to the 5.2.0 release notes, there are no breaking changes, so the upgrade should be safe.