Details
-
Sub-task
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
3.3.5
Description
aws sdk bundle < 1.12.367 uses a vulnerable versions of netty which is pulling in high severity CVE and creating unhappiness in security scans, even if s3a doesn't use that lib.
The safe version for netty is netty:4.1.86.Final and this is used by aws-java-adk:1.12.367+
Attachments
Issue Links
- is depended upon by
-
HADOOP-18760 3.3.6 Release NOTICE and LICENSE file update
- Open
-
HADOOP-18765 Release 3.3.6
- Resolved
- links to