Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-18197

Update protobuf 3.7.1 to a version without CVE-2021-22569

    XMLWordPrintableJSON

Details

    Description

      The artifact `org.apache.hadoop:hadoop-common` brings in a dependency `com.google.protobuf:protobuf-java:2.5.0`, which is an outdated version released in 2013 and it contains a vulnerability CVE-2021-22569.

      Therefore, requesting you to clarify if this library version is going to be updated in the following releases

      Attachments

        Issue Links

          Activity

            People

              pj.fanning PJ Fanning
              ivan.viaznikov Ivan Viaznikov
              Votes:
              0 Vote for this issue
              Watchers:
              14 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 2.5h
                  2.5h