Uploaded image for project: 'Hadoop YARN'
  1. Hadoop YARN
  2. YARN-11611

Remove json-io to 4.14.1 due to CVE-2023-34610

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 3.4.0
    • 3.4.0
    • yarn
    • Reviewed

    Description

      An issue was discovered in json-io 4.14.0 that allows attackers to cause a denial of service via crafted object that uses cyclic dependencies. de.ruedigermoeller:fst only imports java-util (and through that json-io) as a test dependency, so I think we can safely add an exclusion for it.

      Attachments

        Issue Links

          Activity

            People

              bteke Benjamin Teke
              bteke Benjamin Teke
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: