You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@pulsar.apache.org by "Albert Baker (JIRA)" <ji...@apache.org> on 2019/07/08 17:41:00 UTC

[jira] [Resolved] (PULSAR-3) Upgrade hadoop-mapreduce-client-core-2.7.4.jar to 2.7.5

     [ https://issues.apache.org/jira/browse/PULSAR-3?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Albert Baker resolved PULSAR-3.
-------------------------------
    Resolution: Invalid

This jar only gets pulled in during compile time.  It is not deployed with the system.

> Upgrade hadoop-mapreduce-client-core-2.7.4.jar  to 2.7.5
> --------------------------------------------------------
>
>                 Key: PULSAR-3
>                 URL: https://issues.apache.org/jira/browse/PULSAR-3
>             Project: Pulsar
>          Issue Type: Improvement
>            Reporter: Albert Baker
>            Priority: Major
>              Labels: build, easyfix, security
>   Original Estimate: 5m
>  Remaining Estimate: 5m
>
> OWASP Dependency check reports a /critical/ (severity 10) bug w/2.7.4
> [https://nvd.nist.gov/vuln/detail/CVE-2016-1906]
> Mitigation is to upgrade to 2.7.5
> Please update the pom.xml version #
>  



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)