Details
Description
Current version 2.1.1 has no CVEs but all higher versions have CVEs except for the latest release 2.8.0. Still feels like it would be safer to upgrade.
Currently, causes issues - that will need to be fixed:
```
[ERROR] testBlockReaderLocalWithMlockChanges(org.apache.hadoop.hdfs.client.impl.TestBlockReaderLocal) Time elapsed: 0.414 s <<< ERROR!
java.lang.NoClassDefFoundError: Could not initialize class org.apache.commons.configuration2.interpol.ConfigurationInterpolator$DefaultPrefixLookupsHolder
at org.apache.commons.configuration2.interpol.ConfigurationInterpolator.getDefaultPrefixLookups(ConfigurationInterpolator.java:290)
at org.apache.commons.configuration2.AbstractConfiguration.installDefaultInterpolator(AbstractConfiguration.java:375)
at org.apache.commons.configuration2.AbstractConfiguration.<init>(AbstractConfiguration.java:122)
at org.apache.commons.configuration2.BaseConfiguration.<init>(BaseConfiguration.java:37)
at org.apache.commons.configuration2.PropertiesConfiguration.<init>(PropertiesConfiguration.java:1059)
at org.apache.hadoop.metrics2.impl.MetricsConfig.loadFirst(MetricsConfig.java:114)
at org.apache.hadoop.metrics2.impl.MetricsConfig.create(MetricsConfig.java:97)
at org.apache.hadoop.metrics2.impl.MetricsSystemImpl.configure(MetricsSystemImpl.java:482)
at org.apache.hadoop.metrics2.impl.MetricsSystemImpl.start(MetricsSystemImpl.java:188)
at org.apache.hadoop.metrics2.impl.MetricsSystemImpl.init(MetricsSystemImpl.java:163)
at org.apache.hadoop.metrics2.lib.DefaultMetricsSystem.init(DefaultMetricsSystem.java:62)
at org.apache.hadoop.metrics2.lib.DefaultMetricsSystem.initialize(DefaultMetricsSystem.java:58)
at org.apache.hadoop.hdfs.server.namenode.NameNode.createNameNode(NameNode.java:1780)
```
Attachments
Issue Links
- is related to
-
HADOOP-18492 upgrade commons-text to 1.10.0
- Resolved
-
HADOOP-18497 Upgrade commons-text version to fix CVE-2022-42889
- Resolved
- relates to
-
PHOENIX-7181 Do not declare commons-configuration2 dependency
- Resolved
- links to