Uploaded image for project: 'Ratis'
  1. Ratis
  2. RATIS-294

Fix ratis-hadoop CVEs

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Blocker
    • Resolution: Fixed
    • None
    • 0.3.0
    • HadoopRPC

    Description

      There are multiple CVEs found in ratis-hadoop.

      • CVE-2012-4449 | High org.apache.ratis:ratis-hadoop:0.3.0-SNAPSHOT
      • CVE-2016-5001 | Low org.apache.ratis:ratis-hadoop:0.3.0-SNAPSHOT
      • CVE-2017-3161 | Medium org.apache.ratis:ratis-hadoop:0.3.0-SNAPSHOT
      • CVE-2017-3162 | High org.apache.ratis:ratis-hadoop:0.3.0-SNAPSHOT

      It is very likely that the CVEs come from the Hadoop dependency. We should either update the Hadoop version or temporarily remove Hadoop dependency in order to fix the CVEs.

      Attachments

        1. r294_20180921.patch
          0.4 kB
          Tsz-wo Sze

        Activity

          People

            szetszwo Tsz-wo Sze
            szetszwo Tsz-wo Sze
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: