Details
-
Task
-
Status: Closed
-
Major
-
Resolution: Duplicate
-
3.0.0, 3.1.0, 3.2.0, 3.3.0
-
None
-
None
Description
Currently, Spark uses libthrift 0.12, which has reported high severity security vulnerabilities https://snyk.io/vuln/maven:org.apache.thrift%3Alibthrift
Upgrade to 0.14 to get rid of vulnerabilities.
Attachments
Issue Links
- is blocked by
-
HIVE-21498 Upgrade Thrift to 0.13.0
- Closed
-
HIVE-25098 [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.1
- Closed
- is duplicated by
-
SPARK-36994 Upgrade Apache Thrift
- Closed
-
SPARK-37626 Upgrade libthrift to 0.15.0
- Closed
- is related to
-
SPARK-47018 Upgrade built-in Hive to 2.3.10
- Resolved
- is superceded by
-
SPARK-47018 Upgrade built-in Hive to 2.3.10
- Resolved
- links to