the answer there is the web application catalog uses node.js v12.22.1
https://github.com/apache/hadoop/pull/2591

On Wed, 31 Dec 2025 at 12:14, Steve Loughran <[email protected]> wrote:

>
> While off for xmas I see someone announced a way to run arbitrary code on
> any server running node.js/react.js
>
> https://react2shell.com/
>
> I can't really tell by scanning the .js files in the yarn project whether
> we do or don't. There are certainly strings like "your version of Node",
> which worries me.
>
> I was planning to kick off an rc0 of 3.4.3 today just so say "rc0 came out
> in 2025" but we may need to really push for a release with this patch in
>

Reply via email to