Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Duplicate
-
3.3.1
-
None
Description
Our static vulnerability scanner (Fortify On Demand) detected NVD - CVE-2021-0341 (nist.gov) in our application. We traced the vulnerability to a transitive dependency coming from hadoop-hdfs-client, which depends on okhttp@2.7.5 (hadoop/pom.xml at trunk · apache/hadoop (github.com)). To resolve this issue, okhttp should be upgraded to 4.9.2+ (ref: CVE-2021-0341 · Issue #6724 · square/okhttp (github.com)).
Attachments
Issue Links
- duplicates
-
HDFS-16453 Upgrade okhttp from 2.7.5 to 4.9.3
- Resolved
- links to