Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-18858

Upgrade guava due to CVE

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Duplicate
    • 3.3.6
    • None
    • hadoop-thirdparty
    • None

    Description

      Update guava to 32.0.1 or higher due to CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-2976

      hadoop-shaded-guava 1.1.1 is currently using 30.1.1-jre per security scanning tools

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              andrewkstory Andrew Story
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: