Uploaded image for project: 'Flink'
  1. Flink
  2. FLINK-36800

Upgrade hadoop-aws to avoid CVE-2019-14887

    XMLWordPrintableJSON

Details

    Description

      wildfly-openssl is used as SSL provider by hadoop-aws.

       

      Currently, Flink depends on hadoop-aws 3.3.4 including wildfly-openssl 1.0.7 being vulnerable. We should update hadoop-aws to include a later version of the SSL provider.

      Attachments

        Issue Links

          Activity

            People

              fpaul Fabian Paul
              fpaul Fabian Paul
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated: