Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-16690

Update dependency com.nimbusds:nimbus-jose-jwt due to security vulnerability

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Done
    • 3.2.1
    • None
    • auth
    • None

    Description

      Apache Hadoop Auth org.apache.hadoop:hadoop-auth:3.2.1 define dependency to com.nimbusds:nimbus-jose-jwt:4.41.1. There is a known security vulnerability for nimbus-jose-jwt: CVE-2019-17195. Can you upgrade to v7.9 or higher?

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              dawinter DW
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: