Uploaded image for project: 'Flink'
  1. Flink
  2. FLINK-28798

Upgrade JDOM version to 2.0.6.1 in order to resolve CVE-2021-33813

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Done
    • 1.13.6
    • None
    • FileSystems
    • None

    Description

      The flink-oss-fs-hadoop module(flink/flink-filesystems/flink-oss-fs-hadoop/pom.xml) has aliyun-sdk-oss:3.4.1 as dependency. The version of jdom in aliyun-sdk-oss:3.4.1 is 1.1 which is vulnerable. The aliyun-sdk-oss:3.14.1 has jdom:2.0.6.1. Even the flink:1.15 has aliyun-sdk-oss:3.4.1 only. Please upgrade aliyun-sdk-oss to 3.14.1

      Attachments

        Activity

          People

            Unassigned Unassigned
            bilna123 Bilna
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: