We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent a626728 commit 33998abCopy full SHA for 33998ab
presto-kafka/pom.xml
@@ -72,6 +72,20 @@
72
<dependency>
73
<groupId>org.apache.kafka</groupId>
74
<artifactId>kafka-clients</artifactId>
75
+ <exclusions>
76
+ <exclusion>
77
+ <groupId>org.lz4</groupId>
78
+ <artifactId>lz4-java</artifactId>
79
+ </exclusion>
80
+ </exclusions>
81
+ </dependency>
82
+
83
+ <!-- CVE-2025-12183: Override vulnerable lz4-java from kafka-clients -->
84
+ <dependency>
85
+ <groupId>at.yawk.lz4</groupId>
86
87
+ <version>1.10.2</version>
88
+ <scope>runtime</scope>
89
</dependency>
90
91
0 commit comments