Details
-
Bug
-
Status: Closed
-
Blocker
-
Resolution: Fixed
-
1.2.1
-
None
Description
Currently the commons-collections (3.2.1) library allows for invocation of arbitrary code through InvokerTransformer, need to bump the version of commons-collections from 3.2.1 to 3.2.2 to resolve this issue.
Results of mvn dependency:tree:
[INFO] ------------------------------------------------------------------------
[INFO] Building Hive HPL/SQL 2.0.0-SNAPSHOT
[INFO] ------------------------------------------------------------------------
[INFO]
[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ hive-hplsql ---
[INFO] org.apache.hive:hive-hplsql:jar:2.0.0-SNAPSHOT
[INFO] +- com.google.guava:guava:jar:14.0.1:compile
[INFO] +- commons-collections:commons-collections:jar:3.2.1:compile
[INFO] ------------------------------------------------------------------------ [INFO] Building Hive Packaging 2.0.0-SNAPSHOT [INFO] ------------------------------------------------------------------------ [INFO] +- org.apache.hive:hive-hbase-handler:jar:2.0.0-SNAPSHOT:compile [INFO] | +- org.apache.hbase:hbase-server:jar:1.1.1:compile [INFO] | | +- commons-collections:commons-collections:jar:3.2.1:compile
[INFO] ------------------------------------------------------------------------
[INFO] Building Hive Common 2.0.0-SNAPSHOT
[INFO] ------------------------------------------------------------------------
[INFO]
[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ hive-common ---
[INFO] +- org.apache.hadoop:hadoop-common:jar:2.6.0:compile
[INFO] | +- commons-collections:commons-collections:jar:3.2.1:compile
Hadoop-Common dependency also found in: LLAP, Serde, Storage, Shims, Shims Common, Shims Scheduler)
[INFO] ------------------------------------------------------------------------
[INFO] Building Hive Ant Utilities 2.0.0-SNAPSHOT
[INFO] ------------------------------------------------------------------------
[INFO]
[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ hive-ant ---
[INFO] | +- commons-collections:commons-collections:jar:3.1:compile
[INFO] [INFO] ------------------------------------------------------------------------ [INFO] Building Hive Accumulo Handler 2.0.0-SNAPSHOT [INFO] ------------------------------------------------------------------------ [INFO] +- org.apache.accumulo:accumulo-core:jar:1.6.0:compile [INFO] | +- commons-collections:commons-collections:jar:3.2.1:compile
Attachments
Attachments
Issue Links
- links to