Uploaded image for project: 'Hadoop YARN'
  1. Hadoop YARN
  2. YARN-11356

Upgrade DataTables to 1.11.5 to fix CVEs

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 3.3.4
    • 3.4.0
    • yarn
    • Reviewed

    Description

      This ticket is intended to fix the following CVEs in the DataTables.net lib, by upgrading the lib to 1.11.5 

      CVE-2020-28458 (HIGH severity) - All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.

      https://nvd.nist.gov/vuln/detail/CVE-2020-28458

      CVE-2021-23445 (MEDIUM severity) - This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

      https://nvd.nist.gov/vuln/detail/CVE-2021-23445

      Attachments

        Issue Links

          Activity

            People

              bkosztolnik Bence Kosztolnik
              bkosztolnik Bence Kosztolnik
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: