You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@drill.apache.org by "ASF GitHub Bot (Jira)" <ji...@apache.org> on 2022/01/30 14:31:00 UTC
[jira] [Commented] (DRILL-8116) Upgrade Apache Xerces because of CVE-2022-23437
[ https://issues.apache.org/jira/browse/DRILL-8116?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17484365#comment-17484365 ]
ASF GitHub Bot commented on DRILL-8116:
---------------------------------------
kingswanwho opened a new pull request #2443:
URL: https://github.com/apache/drill/pull/2443
# [DRILL-8116](https://issues.apache.org/jira/browse/DRILL-8116): Upgrade Apache Xerces because of CVE-2022-23437
## Description
Upgrade Apache Xerces because of CVE-2022-23437
## Documentation
please refer to https://github.com/advisories/GHSA-h65f-jvqw-m9fj
## Testing
Check dependency by "mvn dependency:tree" and all dependencies which related to Xerces have been upgraded to 2.12.2
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: dev-unsubscribe@drill.apache.org
For queries about this service, please contact Infrastructure at:
users@infra.apache.org
> Upgrade Apache Xerces because of CVE-2022-23437
> -----------------------------------------------
>
> Key: DRILL-8116
> URL: https://issues.apache.org/jira/browse/DRILL-8116
> Project: Apache Drill
> Issue Type: Bug
> Reporter: Jingchuan Hu
> Priority: Major
>
> Please refer to https://github.com/advisories/GHSA-h65f-jvqw-m9fj
--
This message was sent by Atlassian Jira
(v8.20.1#820001)