Uploaded image for project: 'Flink'
  1. Flink
  2. FLINK-25694

Upgrade Presto to resolve GSON/Alluxio Vulnerability

    XMLWordPrintableJSON

Details

    Description

      GSON has a bug, which was fixed in 2.8.9, see https://github.com/google/gson/pull/1991. This results in the possibility for DOS attacks.

      GSON is included in the `flink-s3-fs-presto` plugin, because Alluxio includes it in their shaded client. I've opened an issue in Alluxio: https://github.com/Alluxio/alluxio/issues/14868. When that is fixed, the plugin also needs to be updated.

      Attachments

        Activity

          People

            davidnperkins David Perkins
            davidnperkins David Perkins
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: