Skip to content

Commit 0fd4593

Browse files
authored
KAFKA-19520: Bump Commons-Lang for CVE-2025-48924 (apache#20433)
Bump Commons-Lang for CVE-2025-48924. Signed-off-by: Federico Valeri <[email protected]> Reviewers: Mickael Maison <[email protected]>
1 parent 5507c22 commit 0fd4593

File tree

3 files changed

+4
-1
lines changed

3 files changed

+4
-1
lines changed

LICENSE-binary

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -212,7 +212,7 @@ commons-cli-1.4
212212
commons-collections-3.2.2
213213
commons-digester-2.1
214214
commons-io-2.14.0
215-
commons-lang3-3.12.0
215+
commons-lang3-3.18.0
216216
commons-logging-1.3.5
217217
commons-validator-1.7
218218
error_prone_annotations-2.10.0

build.gradle

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -165,6 +165,7 @@ allprojects {
165165
libs.reload4j,
166166
// Workaround before `commons-validator` has new release. See KAFKA-19359.
167167
libs.commonsBeanutils,
168+
libs.commonsLang
168169
)
169170
}
170171
}

gradle/dependencies.gradle

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,7 @@ versions += [
9292
commonsCli: "1.4",
9393
commonsIo: "2.14.0", // ZooKeeper dependency. Do not use, this is going away.
9494
commonsBeanutils: "1.11.0",
95+
commonsLang: "3.18.0",
9596
commonsValidator: "1.7",
9697
dropwizardMetrics: "4.1.12.1",
9798
gradle: "8.10.2",
@@ -184,6 +185,7 @@ libs += [
184185
commonsCli: "commons-cli:commons-cli:$versions.commonsCli",
185186
commonsIo: "commons-io:commons-io:$versions.commonsIo",
186187
commonsBeanutils: "commons-beanutils:commons-beanutils:$versions.commonsBeanutils",
188+
commonsLang: "org.apache.commons:commons-lang3:$versions.commonsLang",
187189
commonsValidator: "commons-validator:commons-validator:$versions.commonsValidator",
188190
jacksonAnnotations: "com.fasterxml.jackson.core:jackson-annotations:$versions.jackson",
189191
jacksonDatabind: "com.fasterxml.jackson.core:jackson-databind:$versions.jackson",

0 commit comments

Comments
 (0)