Skip to content

Commit ce824d8

Browse files
committed
[NOID] Update lettuce-core to 6.5.4.RELEASE to mitigate CVE-2024-47535, CVE-2025-24970 and CVE-2025-25193
1 parent 0403d53 commit ce824d8

File tree

5 files changed

+60
-60
lines changed

5 files changed

+60
-60
lines changed

LICENSES.txt

Lines changed: 28 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@ Apache-2.0
3232
commons-beanutils-1.9.4.jar
3333
commons-cli-1.5.0.jar
3434
commons-codec-1.16.1.jar
35+
commons-codec-1.18.0.jar
3536
commons-collections-3.2.2.jar
3637
commons-collections4-4.4.jar
3738
commons-compress-1.26.0.jar
@@ -58,7 +59,7 @@ Apache-2.0
5859
ehcache-3.8.2.jar
5960
error_prone_annotations-2.18.0.jar
6061
failureaccess-1.0.1.jar
61-
flatbuffers-java-23.5.26.jar
62+
flatbuffers-java-25.2.10.jar
6263
fst-2.50.jar
6364
gson-2.9.0.jar
6465
guava-32.0.1-jre.jar
@@ -99,22 +100,21 @@ Apache-2.0
99100
jPowerShell-3.0.jar
100101
jProcesses-1.6.5.jar
101102
jackson-annotations-2.15.2.jar
102-
jackson-annotations-2.17.2.jar
103+
jackson-annotations-2.18.3.jar
103104
jackson-core-2.15.2.jar
104-
jackson-core-2.17.2.jar
105+
jackson-core-2.18.3.jar
105106
jackson-databind-2.15.2.jar
106-
jackson-databind-2.17.2.jar
107-
jackson-dataformat-cbor-2.17.2.jar
108-
jackson-dataformat-csv-2.17.2.jar
109-
jackson-dataformat-yaml-2.17.0.jar
110-
jackson-datatype-jsr310-2.17.0.jar
111-
jackson-datatype-jsr310-2.17.2.jar
107+
jackson-databind-2.18.3.jar
108+
jackson-dataformat-cbor-2.18.3.jar
109+
jackson-dataformat-csv-2.18.3.jar
110+
jackson-dataformat-yaml-2.18.3.jar
111+
jackson-datatype-jsr310-2.18.3.jar
112112
jackson-jaxrs-base-2.15.2.jar
113-
jackson-jaxrs-base-2.17.2.jar
113+
jackson-jaxrs-base-2.18.3.jar
114114
jackson-jaxrs-json-provider-2.15.2.jar
115-
jackson-jaxrs-json-provider-2.17.2.jar
115+
jackson-jaxrs-json-provider-2.18.3.jar
116116
jackson-module-jaxb-annotations-2.15.2.jar
117-
jackson-module-jaxb-annotations-2.17.2.jar
117+
jackson-module-jaxb-annotations-2.18.3.jar
118118
jakarta.validation-api-2.0.2.jar
119119
jamm-0.3.3.jar
120120
javapoet-1.13.0.jar
@@ -164,11 +164,11 @@ Apache-2.0
164164
mercator_2.12-0.2.1.jar
165165
metrics-core-3.2.4.jar
166166
netty-all-4.1.100.Final.jar
167-
netty-buffer-4.1.119.Final.jar
168-
netty-codec-4.1.119.Final.jar
167+
netty-buffer-4.1.126.Final.jar
168+
netty-codec-4.1.126.Final.jar
169169
netty-codec-dns-4.1.100.Final.jar
170170
netty-codec-haproxy-4.1.100.Final.jar
171-
netty-codec-http-4.1.119.Final.jar
171+
netty-codec-http-4.1.126.Final.jar
172172
netty-codec-http2-4.1.100.Final.jar
173173
netty-codec-memcache-4.1.100.Final.jar
174174
netty-codec-mqtt-4.1.100.Final.jar
@@ -177,24 +177,24 @@ Apache-2.0
177177
netty-codec-socks-4.1.100.Final.jar
178178
netty-codec-stomp-4.1.100.Final.jar
179179
netty-codec-xml-4.1.100.Final.jar
180-
netty-common-4.1.119.Final.jar
181-
netty-handler-4.1.119.Final.jar
180+
netty-common-4.1.126.Final.jar
181+
netty-handler-4.1.126.Final.jar
182182
netty-handler-proxy-4.1.100.Final.jar
183183
netty-handler-ssl-ocsp-4.1.100.Final.jar
184-
netty-resolver-4.1.119.Final.jar
184+
netty-resolver-4.1.126.Final.jar
185185
netty-resolver-dns-4.1.100.Final.jar
186186
netty-resolver-dns-classes-macos-4.1.100.Final.jar
187187
netty-resolver-dns-native-macos-4.1.100.Final-osx-aarch_64.jar
188188
netty-resolver-dns-native-macos-4.1.100.Final-osx-x86_64.jar
189-
netty-transport-4.1.119.Final.jar
190-
netty-transport-classes-epoll-4.1.119.Final.jar
189+
netty-transport-4.1.126.Final.jar
190+
netty-transport-classes-epoll-4.1.126.Final.jar
191191
netty-transport-classes-kqueue-4.1.100.Final.jar
192-
netty-transport-native-epoll-4.1.119.Final-linux-aarch_64.jar
193-
netty-transport-native-epoll-4.1.119.Final-linux-x86_64.jar
194-
netty-transport-native-epoll-4.1.119.Final.jar
192+
netty-transport-native-epoll-4.1.126.Final-linux-aarch_64.jar
193+
netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar
194+
netty-transport-native-epoll-4.1.126.Final.jar
195195
netty-transport-native-kqueue-4.1.100.Final-osx-aarch_64.jar
196196
netty-transport-native-kqueue-4.1.100.Final-osx-x86_64.jar
197-
netty-transport-native-unix-common-4.1.119.Final.jar
197+
netty-transport-native-unix-common-4.1.126.Final.jar
198198
netty-transport-rxtx-4.1.100.Final.jar
199199
netty-transport-sctp-4.1.100.Final.jar
200200
netty-transport-udt-4.1.100.Final.jar
@@ -218,7 +218,7 @@ Apache-2.0
218218
shiro-crypto-hash-1.13.0.jar
219219
shiro-event-1.13.0.jar
220220
shiro-lang-1.13.0.jar
221-
snakeyaml-2.2.jar
221+
snakeyaml-2.3.jar
222222
snappy-java-1.1.10.4.jar
223223
websocket-api-9.4.53.v20231009.jar
224224
websocket-client-9.4.53.v20231009.jar
@@ -1872,7 +1872,7 @@ Eclipse Distribution License - v 1.0
18721872
istack-commons-runtime-3.0.8.jar
18731873
jakarta.activation-api-1.2.1.jar
18741874
jakarta.activation-api-1.2.2.jar
1875-
jakarta.xml.bind-api-2.3.3.jar
1875+
jakarta.xml.bind-api-2.3.2.jar
18761876
jaxb-runtime-2.3.2.jar
18771877
jersey-client-2.34.jar
18781878
jersey-container-servlet-2.34.jar
@@ -2832,7 +2832,7 @@ MIT
28322832
bcutil-jdk18on-1.78.1.jar
28332833
bcutil-jdk18on-1.78.jar
28342834
cassandra-1.17.6.jar
2835-
checker-qual-3.42.0.jar
2835+
checker-qual-3.33.0.jar
28362836
chromadb-1.19.7.jar
28372837
couchbase-1.17.6.jar
28382838
database-commons-1.17.6.jar
@@ -2855,7 +2855,7 @@ MIT
28552855
qdrant-1.19.7.jar
28562856
reactive-streams-1.0.4.jar
28572857
slf4j-api-1.7.36.jar
2858-
slf4j-api-2.0.11.jar
2858+
slf4j-api-2.0.17.jar
28592859
slf4j-nop-1.7.30.jar
28602860
slf4j-reload4j-1.7.36.jar
28612861
testcontainers-1.19.7.jar

NOTICE.txt

Lines changed: 28 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -62,6 +62,7 @@ Apache-2.0
6262
commons-beanutils-1.9.4.jar
6363
commons-cli-1.5.0.jar
6464
commons-codec-1.16.1.jar
65+
commons-codec-1.18.0.jar
6566
commons-collections-3.2.2.jar
6667
commons-collections4-4.4.jar
6768
commons-compress-1.26.0.jar
@@ -88,7 +89,7 @@ Apache-2.0
8889
ehcache-3.8.2.jar
8990
error_prone_annotations-2.18.0.jar
9091
failureaccess-1.0.1.jar
91-
flatbuffers-java-23.5.26.jar
92+
flatbuffers-java-25.2.10.jar
9293
fst-2.50.jar
9394
gson-2.9.0.jar
9495
guava-32.0.1-jre.jar
@@ -129,22 +130,21 @@ Apache-2.0
129130
jPowerShell-3.0.jar
130131
jProcesses-1.6.5.jar
131132
jackson-annotations-2.15.2.jar
132-
jackson-annotations-2.17.2.jar
133+
jackson-annotations-2.18.3.jar
133134
jackson-core-2.15.2.jar
134-
jackson-core-2.17.2.jar
135+
jackson-core-2.18.3.jar
135136
jackson-databind-2.15.2.jar
136-
jackson-databind-2.17.2.jar
137-
jackson-dataformat-cbor-2.17.2.jar
138-
jackson-dataformat-csv-2.17.2.jar
139-
jackson-dataformat-yaml-2.17.0.jar
140-
jackson-datatype-jsr310-2.17.0.jar
141-
jackson-datatype-jsr310-2.17.2.jar
137+
jackson-databind-2.18.3.jar
138+
jackson-dataformat-cbor-2.18.3.jar
139+
jackson-dataformat-csv-2.18.3.jar
140+
jackson-dataformat-yaml-2.18.3.jar
141+
jackson-datatype-jsr310-2.18.3.jar
142142
jackson-jaxrs-base-2.15.2.jar
143-
jackson-jaxrs-base-2.17.2.jar
143+
jackson-jaxrs-base-2.18.3.jar
144144
jackson-jaxrs-json-provider-2.15.2.jar
145-
jackson-jaxrs-json-provider-2.17.2.jar
145+
jackson-jaxrs-json-provider-2.18.3.jar
146146
jackson-module-jaxb-annotations-2.15.2.jar
147-
jackson-module-jaxb-annotations-2.17.2.jar
147+
jackson-module-jaxb-annotations-2.18.3.jar
148148
jakarta.validation-api-2.0.2.jar
149149
jamm-0.3.3.jar
150150
javapoet-1.13.0.jar
@@ -194,11 +194,11 @@ Apache-2.0
194194
mercator_2.12-0.2.1.jar
195195
metrics-core-3.2.4.jar
196196
netty-all-4.1.100.Final.jar
197-
netty-buffer-4.1.119.Final.jar
198-
netty-codec-4.1.119.Final.jar
197+
netty-buffer-4.1.126.Final.jar
198+
netty-codec-4.1.126.Final.jar
199199
netty-codec-dns-4.1.100.Final.jar
200200
netty-codec-haproxy-4.1.100.Final.jar
201-
netty-codec-http-4.1.119.Final.jar
201+
netty-codec-http-4.1.126.Final.jar
202202
netty-codec-http2-4.1.100.Final.jar
203203
netty-codec-memcache-4.1.100.Final.jar
204204
netty-codec-mqtt-4.1.100.Final.jar
@@ -207,24 +207,24 @@ Apache-2.0
207207
netty-codec-socks-4.1.100.Final.jar
208208
netty-codec-stomp-4.1.100.Final.jar
209209
netty-codec-xml-4.1.100.Final.jar
210-
netty-common-4.1.119.Final.jar
211-
netty-handler-4.1.119.Final.jar
210+
netty-common-4.1.126.Final.jar
211+
netty-handler-4.1.126.Final.jar
212212
netty-handler-proxy-4.1.100.Final.jar
213213
netty-handler-ssl-ocsp-4.1.100.Final.jar
214-
netty-resolver-4.1.119.Final.jar
214+
netty-resolver-4.1.126.Final.jar
215215
netty-resolver-dns-4.1.100.Final.jar
216216
netty-resolver-dns-classes-macos-4.1.100.Final.jar
217217
netty-resolver-dns-native-macos-4.1.100.Final-osx-aarch_64.jar
218218
netty-resolver-dns-native-macos-4.1.100.Final-osx-x86_64.jar
219-
netty-transport-4.1.119.Final.jar
220-
netty-transport-classes-epoll-4.1.119.Final.jar
219+
netty-transport-4.1.126.Final.jar
220+
netty-transport-classes-epoll-4.1.126.Final.jar
221221
netty-transport-classes-kqueue-4.1.100.Final.jar
222-
netty-transport-native-epoll-4.1.119.Final-linux-aarch_64.jar
223-
netty-transport-native-epoll-4.1.119.Final-linux-x86_64.jar
224-
netty-transport-native-epoll-4.1.119.Final.jar
222+
netty-transport-native-epoll-4.1.126.Final-linux-aarch_64.jar
223+
netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar
224+
netty-transport-native-epoll-4.1.126.Final.jar
225225
netty-transport-native-kqueue-4.1.100.Final-osx-aarch_64.jar
226226
netty-transport-native-kqueue-4.1.100.Final-osx-x86_64.jar
227-
netty-transport-native-unix-common-4.1.119.Final.jar
227+
netty-transport-native-unix-common-4.1.126.Final.jar
228228
netty-transport-rxtx-4.1.100.Final.jar
229229
netty-transport-sctp-4.1.100.Final.jar
230230
netty-transport-udt-4.1.100.Final.jar
@@ -248,7 +248,7 @@ Apache-2.0
248248
shiro-crypto-hash-1.13.0.jar
249249
shiro-event-1.13.0.jar
250250
shiro-lang-1.13.0.jar
251-
snakeyaml-2.2.jar
251+
snakeyaml-2.3.jar
252252
snappy-java-1.1.10.4.jar
253253
websocket-api-9.4.53.v20231009.jar
254254
websocket-client-9.4.53.v20231009.jar
@@ -324,7 +324,7 @@ Eclipse Distribution License - v 1.0
324324
istack-commons-runtime-3.0.8.jar
325325
jakarta.activation-api-1.2.1.jar
326326
jakarta.activation-api-1.2.2.jar
327-
jakarta.xml.bind-api-2.3.3.jar
327+
jakarta.xml.bind-api-2.3.2.jar
328328
jaxb-runtime-2.3.2.jar
329329
jersey-client-2.34.jar
330330
jersey-container-servlet-2.34.jar
@@ -434,7 +434,7 @@ MIT
434434
bcutil-jdk18on-1.78.1.jar
435435
bcutil-jdk18on-1.78.jar
436436
cassandra-1.17.6.jar
437-
checker-qual-3.42.0.jar
437+
checker-qual-3.33.0.jar
438438
chromadb-1.19.7.jar
439439
couchbase-1.17.6.jar
440440
database-commons-1.17.6.jar
@@ -457,7 +457,7 @@ MIT
457457
qdrant-1.19.7.jar
458458
reactive-streams-1.0.4.jar
459459
slf4j-api-1.7.36.jar
460-
slf4j-api-2.0.11.jar
460+
slf4j-api-2.0.17.jar
461461
slf4j-nop-1.7.30.jar
462462
slf4j-reload4j-1.7.36.jar
463463
testcontainers-1.19.7.jar

docs/asciidoc/modules/ROOT/pages/database-integration/redis.adoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ Here is a list of all available Redis procedures:
4545
== Install Dependencies
4646

4747
The Redis procedures have dependencies on a client library that is not included in the APOC Library.
48-
You can download it from https://github.com/lettuce-io/lettuce-core/releases/tag/6.2.5.RELEASE[the lettuce-core repository](except for `netty` jars because they are already included within neo4j)
48+
You can download it from https://github.com/lettuce-io/lettuce-core/releases/tag/6.5.4.RELEASE[the lettuce-core repository](except for `netty` jars because they are already included within neo4j)
4949
or https://github.com/neo4j-contrib/neo4j-apoc-procedures/releases/download/{apoc-release}/apoc-redis-dependencies-{apoc-release}.jar[apoc repository]
5050
Once that file is downloaded, it should be placed in the `plugins` directory and the Neo4j Server restarted.
5151

extra-dependencies/redis/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jar {
1919
}
2020

2121
dependencies {
22-
implementation group: 'io.lettuce', name: 'lettuce-core', version: '6.2.5.RELEASE', {
22+
implementation group: 'io.lettuce', name: 'lettuce-core', version: '6.5.4.RELEASE', {
2323
exclude group: 'io.netty'
2424
}
2525
}

full/build.gradle

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -134,8 +134,8 @@ dependencies {
134134
compileOnly group: 'com.couchbase.client', name: 'java-client', version: '3.3.0', withoutJacksons
135135
testImplementation group: 'com.couchbase.client', name: 'java-client', version: '3.3.0', withoutJacksons
136136

137-
compileOnly group: 'io.lettuce', name: 'lettuce-core', version: '6.2.5.RELEASE'
138-
testImplementation group: 'io.lettuce', name: 'lettuce-core', version: '6.2.5.RELEASE'
137+
compileOnly group: 'io.lettuce', name: 'lettuce-core', version: '6.5.4.RELEASE'
138+
testImplementation group: 'io.lettuce', name: 'lettuce-core', version: '6.5.4.RELEASE'
139139

140140
compileOnly group: 'org.neo4j', name: 'neo4j', version: neo4jVersionEffective
141141

0 commit comments

Comments
 (0)