Uploaded image for project: 'Flume'
  1. Flume
  2. FLUME-3121

Upgrade javax.mail:test dependency

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 1.7.0
    • 1.10.0
    • None
    • hive-cli was upgraded to version 1.2.2

    Description

      Group Artifact Version used Upgrade target
      javax.mail mail 1.4.1 1.5.6

      Note: This artifact was moved to:

      • New Group javax.mail
      • New Artifact javax.mail-api

      Security vulnerability: https://www.cvedetails.com/vulnerability-list/vendor_id-5/product_id-5085/SUN-Javamail.html
      Note: this might be a false alarm. Please double check the CVE.

      Please do:

      • double check the newest version.
      • consider to remove a dependency if better alternative is available.
      • check whether the lib change would introduce a backward incompatibility (in which case please add this label `breaking_change` and fix version should be the next major)

      Excerpt from mvn dependency:tree

      +- org.apache.hive:hive-cli:jar:1.0.0:test
      |  +- org.apache.hive:hive-service:jar:1.0.0:test
      |  |  +- org.eclipse.jetty.aggregate:jetty-all:jar:7.6.0.v20120127:test
      |  |  |  +- javax.mail:mail:jar:1.4.1:test
      

      Attachments

        Activity

          People

            Unassigned Unassigned
            sati Attila Simon
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: