You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@oozie.apache.org by "Ashutosh Gupta (Jira)" <ji...@apache.org> on 2022/02/04 08:20:00 UTC

[jira] [Created] (OOZIE-3653) Upgrade commons-io to 2.8.0

Ashutosh Gupta created OOZIE-3653:
-------------------------------------

             Summary: Upgrade commons-io to 2.8.0
                 Key: OOZIE-3653
                 URL: https://issues.apache.org/jira/browse/OOZIE-3653
             Project: Oozie
          Issue Type: Bug
            Reporter: Ashutosh Gupta


Current commons-io is using `2.4` which has the following vulnerabilities

Direct vulnerabilities:
[CVE-2021-29425|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29425]

Vulnerabilities from dependencies:
[CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]

 

We can upgrade to `2.8.0`



--
This message was sent by Atlassian Jira
(v8.20.1#820001)