From 8442abd4b1bce99ca0f134b6870c1c6c622093fa Mon Sep 17 00:00:00 2001 From: Christoph Pirkl Date: Thu, 14 Mar 2024 12:09:44 +0100 Subject: [PATCH] Add release note --- doc/changes/changes_2.0.4.md | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/doc/changes/changes_2.0.4.md b/doc/changes/changes_2.0.4.md index b29d2fe..81d9d8c 100644 --- a/doc/changes/changes_2.0.4.md +++ b/doc/changes/changes_2.0.4.md @@ -1,12 +1,15 @@ -# Spark Connector Common Java 2.0.4, released 2024-??-?? +# Spark Connector Common Java 2.0.4, released 2024-03-14 -Code name: +Code name: Fix CVE-2024-25710 and CVE-2024-26308 in compile dependency ## Summary -## Features +This release fixes CVE-2024-25710 and CVE-2024-26308 in compile dependency `org.apache.commons:commons-compress:1.24.0`. -* ISSUE_NUMBER: description +## Security + +* #30: Fixed CVE-2024-25710 in `org.apache.commons:commons-compress:jar:1.24.0:compile` +* #32: Fixed CVE-2024-26308 in `org.apache.commons:commons-compress:jar:1.24.0:compile` ## Dependency Updates