Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
Description
flink-fs-hadoop-azure has transitive dependency on jetty-util-ajax:9.3.19, which has a security vulnerability: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7657
This was fixed in 9.3.24.v20180605 (source). Starting from version 3.2.1 hadoop-azure is using this version as well, but for a quick resolution I propose bumping this single dependency for the time being.