-
Notifications
You must be signed in to change notification settings - Fork 3.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
HBASE-27424 Upgrade Jettison for CVE-2022-40149/40150 #4822
Conversation
Jettison versions <= 1.5.0 are subject to CVE-2022-40149 and CVE-2022-40150. Move jettison.version to 1.5.1.
Checked before push with tests in |
🎊 +1 overall
This message was automatically generated. |
The jettison dependency is introduced by hadoop. I'm not sure whether upgrading jettison directly will break hadoop. There is a related issue in hadoop to fix jettison. https://issues.apache.org/jira/browse/HADOOP-18468 Let's check the PR there first to see if there are any breaking changes. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Seems the PR in hadoop side is also just a version upgrading, the only code change is for trunk branch and in test code.
+1
🎊 +1 overall
This message was automatically generated. |
💔 -1 overall
This message was automatically generated. |
Jettison versions <= 1.5.0 are subject to CVE-2022-40149 and CVE-2022-40150. Move jettison.version to 1.5.1. Signed-off-by: Duo Zhang <zhangduo@apache.org>
Jettison versions <= 1.5.0 are subject to CVE-2022-40149 and CVE-2022-40150. Move jettison.version to 1.5.1. Signed-off-by: Duo Zhang <zhangduo@apache.org>
Jettison versions <= 1.5.0 are subject to CVE-2022-40149 and CVE-2022-40150. Move jettison.version to 1.5.1. Signed-off-by: Duo Zhang <zhangduo@apache.org>
Jettison versions <= 1.5.0 are subject to CVE-2022-40149 and CVE-2022-40150.
Move jettison.version to 1.5.1.