This is an automated email from the ASF dual-hosted git repository.

mpapirkovskyy pushed a commit to branch trunk
in repository https://gitbox.apache.org/repos/asf/ambari.git


The following commit(s) were added to refs/heads/trunk by this push:
     new 145ff84  AMBARI-23627. Update Spring dependencies to fix 
CVE-2018-1270. (mpapirkovskyy) (#1135)
145ff84 is described below

commit 145ff84abf6ea04ff6a6a9596573522f81a4afcd
Author: Myroslav Papirkovskyi <[email protected]>
AuthorDate: Mon Apr 30 21:33:50 2018 +0300

    AMBARI-23627. Update Spring dependencies to fix CVE-2018-1270. 
(mpapirkovskyy) (#1135)
---
 ambari-project/pom.xml | 7 ++++++-
 ambari-server/pom.xml  | 5 +++++
 2 files changed, 11 insertions(+), 1 deletion(-)

diff --git a/ambari-project/pom.xml b/ambari-project/pom.xml
index 4a98bda..93ffd4b 100644
--- a/ambari-project/pom.xml
+++ b/ambari-project/pom.xml
@@ -37,7 +37,7 @@
     <swagger.maven.plugin.version>3.1.4</swagger.maven.plugin.version>
     <slf4j.version>1.7.20</slf4j.version>
     <guice.version>4.1.0</guice.version>
-    <spring.version>4.3.7.RELEASE</spring.version>
+    <spring.version>4.3.16.RELEASE</spring.version>
     <fasterxml.jackson.version>2.9.5</fasterxml.jackson.version>
     <forkCount>4</forkCount>
     <reuseForks>false</reuseForks>
@@ -476,6 +476,11 @@
       </dependency>
       <dependency>
         <groupId>org.springframework</groupId>
+        <artifactId>spring-expression</artifactId>
+        <version>${spring.version}</version>
+      </dependency>
+      <dependency>
+        <groupId>org.springframework</groupId>
         <artifactId>spring-messaging</artifactId>
         <version>${spring.version}</version>
       </dependency>
diff --git a/ambari-server/pom.xml b/ambari-server/pom.xml
index 71034d2..8083880 100644
--- a/ambari-server/pom.xml
+++ b/ambari-server/pom.xml
@@ -1462,6 +1462,11 @@
     </dependency>
 
     <dependency>
+      <groupId>org.springframework</groupId>
+      <artifactId>spring-expression</artifactId>
+    </dependency>
+
+    <dependency>
       <groupId>com.sun.jersey.contribs</groupId>
       <artifactId>jersey-spring</artifactId>
       <version>1.19</version>

-- 
To stop receiving notification emails like this one, please contact
[email protected].

Reply via email to