From 11618aeebc706904339abf424b83620625182611 Mon Sep 17 00:00:00 2001 From: maximthomas Date: Tue, 9 Dec 2025 14:00:13 +0300 Subject: [PATCH] CVE-2025-12183 LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS CVE-2025-66566 yawkat LZ4 Java has a possible information leak in Java safe decompressor --- .../openam-cassandra-datastore/pom.xml | 6 +++--- openam-cassandra/openam-cassandra-embedded/pom.xml | 6 +++++- openam-cassandra/pom.xml | 14 ++++++++++---- 3 files changed, 18 insertions(+), 8 deletions(-) diff --git a/openam-cassandra/openam-cassandra-datastore/pom.xml b/openam-cassandra/openam-cassandra-datastore/pom.xml index a4ccda88b4..69fa87e887 100644 --- a/openam-cassandra/openam-cassandra-datastore/pom.xml +++ b/openam-cassandra/openam-cassandra-datastore/pom.xml @@ -12,7 +12,7 @@ * Header, with the fields enclosed by brackets [] replaced by your own identifying * information: "Portions copyright [year] [name of copyright owner]". * - * Copyright 2019 Open Identity Platform Community. + * Copyright 2019-2025 3A Systems LLC. --> 4.0.0 @@ -35,8 +35,8 @@ java-driver-core - org.lz4 - lz4-java + at.yawk.lz4 + lz4-java org.xerial.snappy diff --git a/openam-cassandra/openam-cassandra-embedded/pom.xml b/openam-cassandra/openam-cassandra-embedded/pom.xml index ca74b8e1d0..a550fa9663 100644 --- a/openam-cassandra/openam-cassandra-embedded/pom.xml +++ b/openam-cassandra/openam-cassandra-embedded/pom.xml @@ -12,7 +12,7 @@ * Header, with the fields enclosed by brackets [] replaced by your own identifying * information: "Portions copyright [year] [name of copyright owner]". * - * Copyright 2019 Open Identity Platform Community. + * Copyright 2019-2025 3A Systems LLC. --> 4.0.0 @@ -35,6 +35,10 @@ org.apache.cassandra cassandra-all + + at.yawk.lz4 + lz4-java + com.google.guava failureaccess diff --git a/openam-cassandra/pom.xml b/openam-cassandra/pom.xml index 844b28d851..04079ccfb9 100644 --- a/openam-cassandra/pom.xml +++ b/openam-cassandra/pom.xml @@ -12,7 +12,7 @@ * Header, with the fields enclosed by brackets [] replaced by your own identifying * information: "Portions copyright [year] [name of copyright owner]". * - * Copyright 2019 Open Identity Platform Community. + * Copyright 2019-2025 3A Systems LLC. --> 4.0.0 @@ -50,11 +50,17 @@ org.apache.cassandra cassandra-all 4.0.17 + + + org.lz4 + lz4-java + + - org.lz4 - lz4-java - 1.8.0 + at.yawk.lz4 + lz4-java + 1.10.1 org.xerial.snappy