layout: news_item date: “2022-07-28 08:30:00 +0000” author: francischuang version: 1.22.0 categories: [release] tag: v1-22-0 sha: 71fc0ab component: avatica

Apache Calcite Avatica 1.22.0 is a maintenance release to resolve CVE-2022-36364: Apache Calcite Avatica JDBC driver httpclient_impl connection property can be used as an RCE vector. Users of previous versions of Avatica MUST upgrade to mitigate this vulnerability. For more info please see the entry in the CVE database: CVE-2022-36364.

See the list of [bug fixes and new features]({{ site.baseurl }}/docs/history.html#v1-22-0) for more information.