Uploaded image for project: 'Flume'
  1. Flume
  2. FLUME-3127

Upgrade libfb303 library dependency

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 1.7.0
    • Fix Version/s: 1.8.0
    • Component/s: None
    • Labels:

      Description

      Group Artifact Version used Upgrade target
      org.apache.thrift libthrift 0.9.0 0.9.3,0.10.0
      org.apache.thrift libfb303 0.9.0 0.9.3

      Security vulnerability: http://www.cvedetails.com/cve/CVE-2015-3254/
      Maven repository:

      Please do:

      • CVE might be a false alarm or mistake. Please double check.
      • double check the newest version.
      • consider to remove a dependency if better alternative is available.
      • check whether the lib change would introduce a backward incompatibility (in which case please add this label `breaking_change` and fix version should be the next major)

      Excerpt from mvn dependency:tree

      org.apache.flume:flume-ng-sdk:jar:1.8.0-SNAPSHOT
      \- org.apache.thrift:libthrift:jar:0.9.0:compile
      
      org.apache.flume.flume-ng-sinks:flume-hive-sink:jar:1.8.0-SNAPSHOT
      +- org.apache.hive.hcatalog:hive-hcatalog-streaming:jar:1.0.0:provided
      |  +- org.apache.hive:hive-metastore:jar:1.0.0:provided
      |  |  \- org.apache.thrift:libfb303:jar:0.9.0:provided
      

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                fszabo Ferenc Szabo
                Reporter:
                sati Attila Simon
              • Votes:
                0 Vote for this issue
                Watchers:
                5 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: