Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-45590

okio-1.15.0 CVE-2023-3635

    XMLWordPrintableJSON

Details

    Description

      CVE-2023-3635 is being flagged against okio-1.15.0 present in the Spark 3.5.0 build:

      • ./spark-3.5.0-bin-without-hadoop/jars/okio-1.15.0.jar
      • ./spark-3.5.0-bin-hadoop3/jars/okio-1.15.0.jar

      I don't see okio in the dependency tree, it must be coming in via some profile.

      Attachments

        Activity

          People

            roczei Gabor Roczei
            coheigea Colm O hEigeartaigh
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: