Uploaded image for project: 'Flume'
  1. Flume
  2. FLUME-3132

Upgrade tomcat jasper library dependencies

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • 1.7.0
    • 1.8.0
    • None

    Description

      Group Artifact Version used Upgrade target
      tomcat jasper-compiler 5.5.23 8.5.x
      tomcat jasper-runtime 5.5.23 8.5.x

      Security vulnerability:

      Note: These artifacts were moved to:

      • New Group org.apache.tomcat
      • New Artifact

      Please do:

      • CVE might be a false alarm or mistake. Please double check.
      • double check the newest version.
      • consider to remove a dependency if better alternative is available.
      • check whether the lib change would introduce a backward incompatibility (in which case please add this label `breaking_change` and fix version should be the next major)

      Excerpt from mvn dependency:tree

      org.apache.flume:flume-ng-auth:jar:1.8.0-SNAPSHOT
      +- org.apache.hadoop:hadoop-common:jar:2.4.0:compile
      |  +- tomcat:jasper-compiler:jar:5.5.23:runtime
      |  +- tomcat:jasper-runtime:jar:5.5.23:runtime
      

      Attachments

        Issue Links

          Activity

            People

              fszabo Ferenc Szabo
              sati Attila Simon
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: