Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-18101

Bump aliyun-sdk-oss to 3.13.2 and jdom2 to 2.0.6.1

VotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      The current aliyun-sdk-oss 3.13.0 is affected by CVE-2021-33813 due to jdom 2.0.6. maven-shade-plugin is also affected by the CVE. 

      Bumping aliyun-sdk-oss to 3.13.2 and jdom2 to 2.0.6.1 will resolve this issue

      [INFO] +- org.apache.maven.plugins:maven-shade-plugin:jar:3.2.1:provided
      [INFO] |  +- org.apache.maven.shared:maven-artifact-transfer:jar:0.10.0:provided
      [INFO] |  +- org.jdom:jdom2:jar:2.0.6:provided
      ......
      [INFO] +- com.aliyun.oss:aliyun-sdk-oss:jar:3.13.1:compile
      [INFO] |  +- org.jdom:jdom2:jar:2.0.6:compile
      

       

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            aswinshakil Aswin Shakil
            aswinshakil Aswin Shakil
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 1h 10m
                1h 10m

                Slack

                  Issue deployment