You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@oozie.apache.org by "Ashutosh Gupta (Jira)" <ji...@apache.org> on 2022/02/07 17:46:00 UTC

[jira] [Comment Edited] (OOZIE-3653) Upgrade commons-io to 2.8.0

    [ https://issues.apache.org/jira/browse/OOZIE-3653?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17488284#comment-17488284 ] 

Ashutosh Gupta edited comment on OOZIE-3653 at 2/7/22, 5:45 PM:
----------------------------------------------------------------

Thanks [~dionusos] for your comment. I have attached patch OOZIE-3653-002.patch with commons-io upgraded to 2.11.0


was (Author: groot):
Thanks [~dionusos] for your comment. I have attached patch OOZIE-3653-002.patch with commons-io upgraded to 2.11.0

> Upgrade commons-io to 2.8.0
> ---------------------------
>
>                 Key: OOZIE-3653
>                 URL: https://issues.apache.org/jira/browse/OOZIE-3653
>             Project: Oozie
>          Issue Type: Bug
>    Affects Versions: 5.2.1
>            Reporter: Ashutosh Gupta
>            Assignee: Ashutosh Gupta
>            Priority: Major
>         Attachments: OOZIE-3653-001.patch, OOZIE-3653-002.patch
>
>
> Current commons-io is using 2.4 which has the following vulnerabilities
> Direct vulnerabilities:
> [CVE-2021-29425|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29425]
> Vulnerabilities from dependencies:
> [CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]
>  
> We can upgrade to 2.8.0



--
This message was sent by Atlassian Jira
(v8.20.1#820001)