Highlights
Dependency Vulnerability: 2 prior fixes. Scrutinize any change in this area.
flink-shaded-jsonpath: most-fixed (1 issue). Treat as high-risk during review.
2 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Dependency Vulnerability: The json-path library version 2.7.0 was shipped with known CVEs, requiring an upgrade to 2.9.0. This component is a direct dependency that can expose the application to exploitation if left unpatched.
Dependency Vulnerability: Zookeeper versions 3.7.1/3.8.1 were vulnerable to CVE-2023-44981, a serious flaw. The fix upgraded to 3.7.2 and 3.8.3, emphasizing the criticality of keeping this coordination service patched.