Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-23065

Remove dependency on org.apache.httpcomponents:httpclient before version 4.3.5.1 for Ambari Server

    XMLWordPrintableJSON

Details

    Description

      Remove dependency on org.apache.httpcomponents:httpclient:jar before version 4.3.5.1 due to security concerns. See

      --- maven-dependency-plugin:2.8:tree(default-cli) @ ambari-server ---
       org.apache.ambari:ambari-server:jar:2.6.1.0.0
       +- org.apache.httpcomponents:httpclient:jar:4.2.5:compile
       +- org.apache.ambari:ambari-metrics-common:jar:2.6.1.0.0:compile
       |  \- (org.apache.httpcomponents:httpclient:jar:4.2.5:compile - omitted for duplicate)
       +- org.apache.hadoop:hadoop-auth:jar:2.7.2:compile
       |  \- (org.apache.httpcomponents:httpclient:jar:4.2.5:compile - omitted for duplicate)
       \- org.apache.hadoop:hadoop-common:jar:2.7.2:compile
          \- net.java.dev.jets3t:jets3t:jar:0.9.0:compile
             \- (org.apache.httpcomponents:httpclient:jar:4.1.2:compile - omitted for conflict with 4.2.5)
       

       

      Attachments

        Issue Links

          Activity

            People

              smolnar Sandor Molnar
              smolnar Sandor Molnar
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 2h
                  2h