Skip to content

Commit 375284c

Browse files
authored
CVE-2025-12183 CVE-2025-66566 LZ4 vulnerabilities (#946)
1 parent 1f61ec1 commit 375284c

File tree

3 files changed

+18
-8
lines changed

3 files changed

+18
-8
lines changed

openam-cassandra/openam-cassandra-datastore/pom.xml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
* Header, with the fields enclosed by brackets [] replaced by your own identifying
1313
* information: "Portions copyright [year] [name of copyright owner]".
1414
*
15-
* Copyright 2019 Open Identity Platform Community.
15+
* Copyright 2019-2025 3A Systems LLC.
1616
-->
1717
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
1818
<modelVersion>4.0.0</modelVersion>
@@ -35,8 +35,8 @@
3535
<artifactId>java-driver-core</artifactId>
3636
</dependency>
3737
<dependency>
38-
<groupId>org.lz4</groupId>
39-
<artifactId>lz4-java</artifactId>
38+
<groupId>at.yawk.lz4</groupId>
39+
<artifactId>lz4-java</artifactId>
4040
</dependency>
4141
<dependency>
4242
<groupId>org.xerial.snappy</groupId>

openam-cassandra/openam-cassandra-embedded/pom.xml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
* Header, with the fields enclosed by brackets [] replaced by your own identifying
1313
* information: "Portions copyright [year] [name of copyright owner]".
1414
*
15-
* Copyright 2019 Open Identity Platform Community.
15+
* Copyright 2019-2025 3A Systems LLC.
1616
-->
1717
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
1818
<modelVersion>4.0.0</modelVersion>
@@ -35,6 +35,10 @@
3535
<groupId>org.apache.cassandra</groupId>
3636
<artifactId>cassandra-all</artifactId>
3737
</dependency>
38+
<dependency>
39+
<groupId>at.yawk.lz4</groupId>
40+
<artifactId>lz4-java</artifactId>
41+
</dependency>
3842
<dependency>
3943
<groupId>com.google.guava</groupId>
4044
<artifactId>failureaccess</artifactId>

openam-cassandra/pom.xml

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
* Header, with the fields enclosed by brackets [] replaced by your own identifying
1313
* information: "Portions copyright [year] [name of copyright owner]".
1414
*
15-
* Copyright 2019 Open Identity Platform Community.
15+
* Copyright 2019-2025 3A Systems LLC.
1616
-->
1717
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
1818
<modelVersion>4.0.0</modelVersion>
@@ -50,11 +50,17 @@
5050
<groupId>org.apache.cassandra</groupId>
5151
<artifactId>cassandra-all</artifactId>
5252
<version>4.0.17</version>
53+
<exclusions>
54+
<exclusion>
55+
<groupId>org.lz4</groupId>
56+
<artifactId>lz4-java</artifactId>
57+
</exclusion>
58+
</exclusions>
5359
</dependency>
5460
<dependency>
55-
<groupId>org.lz4</groupId>
56-
<artifactId>lz4-java</artifactId>
57-
<version>1.8.0</version>
61+
<groupId>at.yawk.lz4</groupId>
62+
<artifactId>lz4-java</artifactId>
63+
<version>1.10.1</version>
5864
</dependency>
5965
<dependency>
6066
<groupId>org.xerial.snappy</groupId>

0 commit comments

Comments
 (0)