You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@pulsar.apache.org by "Albert Baker (JIRA)" <ji...@apache.org> on 2019/07/08 17:41:00 UTC
[jira] [Resolved] (PULSAR-3) Upgrade
hadoop-mapreduce-client-core-2.7.4.jar to 2.7.5
[ https://issues.apache.org/jira/browse/PULSAR-3?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Albert Baker resolved PULSAR-3.
-------------------------------
Resolution: Invalid
This jar only gets pulled in during compile time. It is not deployed with the system.
> Upgrade hadoop-mapreduce-client-core-2.7.4.jar to 2.7.5
> --------------------------------------------------------
>
> Key: PULSAR-3
> URL: https://issues.apache.org/jira/browse/PULSAR-3
> Project: Pulsar
> Issue Type: Improvement
> Reporter: Albert Baker
> Priority: Major
> Labels: build, easyfix, security
> Original Estimate: 5m
> Remaining Estimate: 5m
>
> OWASP Dependency check reports a /critical/ (severity 10) bug w/2.7.4
> [https://nvd.nist.gov/vuln/detail/CVE-2016-1906]
> Mitigation is to upgrade to 2.7.5
> Please update the pom.xml version #
>
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)