Uploaded image for project: 'Parquet'
  1. Parquet
  2. PARQUET-2487

Bump io.airlift:aircompressor to 0.27 in parquet-hadoop

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 1.14.0
    • None
    • parquet-hadoop

    Description

      A high severity out-of-bound R/W vulnerability was found in aircompressor and was fixed in version 0.27. parquet-hadoop should be updated from 0.26 to use the new version.

      https://nvd.nist.gov/vuln/detail/CVE-2024-36114

       

      Pull request: https://github.com/apache/parquet-java/pull/1363

      Attachments

        Activity

          People

            Unassigned Unassigned
            utkuaydin Utku Aydin
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment