Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities in Apache Commons IO 2.5 used by Hadoop in Jet #3066

Open
olukas opened this issue Sep 7, 2021 · 0 comments
Open

Vulnerabilities in Apache Commons IO 2.5 used by Hadoop in Jet #3066

olukas opened this issue Sep 7, 2021 · 0 comments
Labels
security Pull requests that address a security vulnerability severity:medium Vulnerability scan classification for Medium Severity issues

Comments

@olukas
Copy link
Collaborator

olukas commented Sep 7, 2021

Jet uses org.apache.hadoop:hadoop-client which uses commons-io:commons-io in version 2.5 which includes following vulnerability:

@olukas olukas added security Pull requests that address a security vulnerability severity:medium Vulnerability scan classification for Medium Severity issues labels Sep 7, 2021
@olukas olukas added this to the 4.5.1 milestone Sep 7, 2021
gurbuzali pushed a commit that referenced this issue Sep 7, 2021
fixes #3064

Update Elasticsearch6 to 6.8.17
fixes #3065

Update commons-io:commons-io to 2.7
fixes #3066

Update Jetty to 9.4.43
fixes #3067
@degerhz degerhz modified the milestones: 4.5.1, 4.5.2 Sep 14, 2021
@frant-hartm frant-hartm modified the milestones: 4.5.2, 4.5.3 Dec 15, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Pull requests that address a security vulnerability severity:medium Vulnerability scan classification for Medium Severity issues
Projects
None yet
Development

No branches or pull requests

3 participants