Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-38262

Upgrade Google guava to version 30.0-jre

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Resolved
    • Major
    • Resolution: Duplicate
    • 3.3.0
    • None
    • Build
    • None

    Description

      This is duplicated many times like in SPARK-32502

      Apache Spark is using com.google.guava:guava version 14.0.1 which has two security issues.

      CVE-2018-10237

      CVE-2020-8908

      We should upgrade to version 30.0

      I will add some links to what I have found about this issue

      HIVE-25617:fix bug introduced by CVE-2020-8908

      Upgrade Guava to 27

      HIVE-21961: Upgrade Hadoop to 3.1.4, Guava to 27.0-jre and Jetty to 9.4.20.v20190813

      Shade Guava manually

      [DISCUSS] Hadoop 3, dropping support for Hadoop 2.x

      Attachments

        Activity

          People

            Unassigned Unassigned
            bjornjorgensen Bjørn Jørgensen
            Votes:
            1 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: