Uploaded image for project: 'Zeppelin'
  1. Zeppelin
  2. ZEPPELIN-5714

Upgrade Spring Framework in zeppelin-livy-0.10.x.jar

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Blocker
    • Resolution: Unresolved
    • 0.10.0, 0.10.1
    • None
    • livy-interpreter

    Description

      We should upgrade the Spring version at Zepelin Livy jar because of cve-2022-22965. The Qualys Scanner finds these packages and raises a warning because of the existence of these files on the system. 

      The found files are: /usr/lib/zeppelin/interpreter/livy/zeppelin-livy-0.10.0.jar (org/springframework/beans/CachedIntrospectionResults.class): CachedIntrospectionResults.class spring 4.3.0-4.3.2

      More Information: 
      Spring Framework: https://spring.io/projects/spring-framework
      Spring project spring-framework release notes: https://github.com/spring-projects/spring-framework/releases
      CVE-2022-22965: https://tanzu.vmware.com/security/cve-2022-22965

      Attachments

        Activity

          People

            Unassigned Unassigned
            jasonmadam Jason-Morries Adam
            Votes:
            2 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated: