Skip to content

1.1.2 Fixed CVE-2025-24970 and CVE-2025-25193

Compare
Choose a tag to compare
@github-actions github-actions released this 13 Feb 16:29
· 1 commit to main since this release
92615b3

This update fixes CVE-2025-24970 and CVE-2025-25193 in transitive netty dependency.
It also updates other dependencies.

Security

Dependency Updates

Compile Dependency Updates

  • Updated com.exasol:exasol-jdbc:24.2.0 to 24.2.1
  • Updated org.apache.logging.log4j:log4j-api:2.24.1 to 2.24.3
  • Updated org.apache.logging.log4j:log4j-core:2.24.1 to 2.24.3
  • Updated org.apache.logging.log4j:log4j-slf4j-impl:2.24.1 to 2.24.3
  • Updated software.amazon.awssdk:cloudwatch:2.29.15 to 2.30.19
  • Updated software.amazon.awssdk:secretsmanager:2.29.15 to 2.30.19

Test Dependency Updates

  • Removed com.amazonaws:aws-java-sdk-s3:1.12.778
  • Updated com.exasol:exasol-testcontainers:7.1.1 to 7.1.3
  • Updated nl.jqno.equalsverifier:equalsverifier:3.17.3 to 3.19
  • Updated org.junit.jupiter:junit-jupiter:5.11.3 to 5.11.4
  • Updated org.mockito:mockito-core:5.14.2 to 5.15.2
  • Updated org.testcontainers:junit-jupiter:1.20.3 to 1.20.4
  • Updated org.testcontainers:localstack:1.20.3 to 1.20.4

Plugin Dependency Updates

  • Updated com.exasol:project-keeper-maven-plugin:4.4.0 to 4.5.0
  • Updated org.apache.maven.plugins:maven-failsafe-plugin:3.5.1 to 3.5.2
  • Updated org.apache.maven.plugins:maven-site-plugin:3.9.1 to 3.21.0
  • Updated org.apache.maven.plugins:maven-surefire-plugin:3.5.1 to 3.5.2
  • Updated org.codehaus.mojo:versions-maven-plugin:2.17.1 to 2.18.0
  • Updated org.sonarsource.scanner.maven:sonar-maven-plugin:4.0.0.4121 to 5.0.0.4389