Details
-
Improvement
-
Status: Resolved
-
Blocker
-
Resolution: Fixed
-
3.3.5, 3.3.4
-
Reviewed
Description
Latest 3.3.4 version of hadoop-common and hadoop-client-runtime includes commons-net in version 3.6, which has vulnerability CVE-2021-37533. Need to upgrade it to 3.9 to fix.
This is a due diligence patch only; by the time the caller encounters the CVE they must have already provided their username and password to a malicious ftp server.
Attachments
Issue Links
- relates to
-
NET-711 Add FTP option to toggle use of return host like cURL
- Resolved
-
HADOOP-18361 Update commons-net from 3.6 to 3.8.0.
- Resolved
- links to