Uploaded image for project: 'Hadoop HDFS'
  1. Hadoop HDFS
  2. HDFS-16860

Upgrade moment.min.js to 2.29.4

    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      Upgrade moment.min.js to 2.29.4 to resolve https://nvd.nist.gov/vuln/detail/CVE-2022-31129

      "Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4"

      this only appears to affect the UI, not the yarn services, so it is a self-harm DoS rather than anything important. "if you pass in big strings the ui slows down"

      Attachments

        Issue Links

          Activity

            People

              anuragparvatikar Anurag Parvatikar
              dmmkr D M Murali Krishna Reddy
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: