Details
-
Improvement
-
Status: Closed
-
Blocker
-
Resolution: Fixed
-
1.10.0
Description
hive-metastore depends on derby 10.10/10.4, which are vulnerable to CVE-2015-1832.
We should bump the version to at least 10.12.1.1 .
Assuming that derby is only required for the server and not the client we could potentially even exclude it.
phoenixjiangnan Can you help with this?
Attachments
Issue Links
- links to