In this release, we've enhanced the security and stability of the Collector with added support for security patches and bug fixes.
Security Fixes​
- Upgraded collector JRE to Amazon Corretto Version 8.392.08.1.
- Upgraded
org.apache.commons:commons-compress
to version 1.24.0 to address known security vulnerabilities (CVE-2023-42503). - Upgraded
org.xerial.snappy:snappy-java
to 1.1.10.4 to address known security vulnerabilities (CVE-2023-43642). - Upgraded
org.bouncycastle:bc-fips
to 1.0.2.4 to address known security vulnerabilities (CVE-2022-45146). - Upgraded
com.google.crypto.tink:tink
to 1.11.0 to address known security vulnerabilities (CVE-2022-3510 and CVE-2022-3509).
Bug Fixes​
- Fixed the AWS archive temporary files clean up issue on Windows. If you are facing this issue while upgrading from a previous collector version then a collector restart might be necessary after the upgrade.
- Fixed temporary files issue in Windows installation.