You are viewing a plain text version of this content. The canonical link for it is here.
Posted to common-issues@hadoop.apache.org by "Steve Loughran (Jira)" <ji...@apache.org> on 2022/12/05 13:06:00 UTC

[jira] [Commented] (HADOOP-18540) Upgrade Bouncy Castle to 1.70

    [ https://issues.apache.org/jira/browse/HADOOP-18540?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17643340#comment-17643340 ] 

Steve Loughran commented on HADOOP-18540:
-----------------------------------------

bouncy castle updates always seem to break transient things. i would really like SPARK-41392 fixed before this PR goes in, so if this upgrade triggers another regression there it'll be found sooner rather than later.

We *cannot* backport bc updates unless spark can cope

> Upgrade Bouncy Castle to 1.70
> -----------------------------
>
>                 Key: HADOOP-18540
>                 URL: https://issues.apache.org/jira/browse/HADOOP-18540
>             Project: Hadoop Common
>          Issue Type: Improvement
>            Reporter: D M Murali Krishna Reddy
>            Assignee: D M Murali Krishna Reddy
>            Priority: Major
>              Labels: pull-request-available
>
> Upgrade Bouncycastle to 1.70 to resolve
>  
> |[[sonatype-2021-4916] CWE-327: Use of a Broken or Risky Cryptographic Algorithm|https://ossindex.sonatype.org/vulnerability/sonatype-2021-4916?component-type=maven&component-name=org.bouncycastle/bcprov-jdk15on]|
> |[[sonatype-2019-0673] CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion')|https://ossindex.sonatype.org/vulnerability/sonatype-2019-0673?component-type=maven&component-name=org.bouncycastle/bcprov-jdk15on]|



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: common-issues-unsubscribe@hadoop.apache.org
For additional commands, e-mail: common-issues-help@hadoop.apache.org