diff --git a/eng/versioning/external_dependencies.txt b/eng/versioning/external_dependencies.txt index bd40c705e6d1..1b8a1ece419d 100644 --- a/eng/versioning/external_dependencies.txt +++ b/eng/versioning/external_dependencies.txt @@ -280,6 +280,9 @@ cosmos_org.testcontainers:kafka;1.21.4 cosmos_org.sourcelab:kafka-connect-client;4.0.4 cosmos_io.confluent:kafka-avro-serializer;7.6.0 cosmos_org.apache.avro:avro;1.11.4 +cosmos_org.apache.logging.log4j:log4j-api;2.25.3 +cosmos_org.apache.logging.log4j:log4j-core;2.25.3 +cosmos_org.apache.logging.log4j:log4j-slf4j-impl;2.25.3 # Maven Tools for Cosmos Kafka connector only # sdk\resourcemanager\azure-resourcemanager\pom.xml diff --git a/sdk/cosmos/azure-cosmos-kafka-connect/CHANGELOG.md b/sdk/cosmos/azure-cosmos-kafka-connect/CHANGELOG.md index 95d5b6501bc3..e278e4a1b379 100644 --- a/sdk/cosmos/azure-cosmos-kafka-connect/CHANGELOG.md +++ b/sdk/cosmos/azure-cosmos-kafka-connect/CHANGELOG.md @@ -9,6 +9,8 @@ #### Bugs Fixed #### Other Changes +* Updated `log4j-api`, `log4j-core` and `log4j-slf4j-impl` test dependencies to `2.25.3` to address [CVE-2025-68161](https://github.com/advisories/GHSA-pgxp-9w8h-vfh4) (Apache Log4j: information disclosure via missing TLS hostname verification). +* Picked up patched versions of `jackson-core` (`2.18.6`) and `netty-codec-http`/`netty-codec-http2` (`4.1.132.Final`) transitively via `azure-cosmos` `4.81.0-beta.1`, addressing [GHSA-72hv-8253-57qq](https://github.com/advisories/GHSA-72hv-8253-57qq), [CVE-2026-33870](https://nvd.nist.gov/vuln/detail/CVE-2026-33870), [CVE-2025-67735](https://nvd.nist.gov/vuln/detail/CVE-2025-67735) and [CVE-2026-33871](https://nvd.nist.gov/vuln/detail/CVE-2026-33871). ### 2.10.0 (2026-05-01) diff --git a/sdk/cosmos/azure-cosmos-kafka-connect/pom.xml b/sdk/cosmos/azure-cosmos-kafka-connect/pom.xml index ec496f401860..27828c2f0243 100644 --- a/sdk/cosmos/azure-cosmos-kafka-connect/pom.xml +++ b/sdk/cosmos/azure-cosmos-kafka-connect/pom.xml @@ -181,21 +181,21 @@ Licensed under the MIT License. org.apache.logging.log4j log4j-slf4j-impl - 2.17.2 + 2.25.3 test org.apache.logging.log4j log4j-api - 2.17.2 + 2.25.3 test org.apache.logging.log4j log4j-core - 2.17.2 + 2.25.3 test