[ 
https://issues.apache.org/jira/browse/HADOOP-13659?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15592173#comment-15592173
 ] 

Sean Mackrory commented on HADOOP-13659:
----------------------------------------

For what it's worth while we wait for a response, upgrading to 2.2.11 is a 
perfectly acceptable outcome here to me. 2.2.2 is referenced by several CVEs. 
While I don't think any of them are critical (IIRC they're considered low risk, 
maybe medium at worst), it's a step in the right direction to upgrade, all 
other things being equal. 2.2.11 resolves all those issues too.

> Upgrade jaxb-api version
> ------------------------
>
>                 Key: HADOOP-13659
>                 URL: https://issues.apache.org/jira/browse/HADOOP-13659
>             Project: Hadoop Common
>          Issue Type: Improvement
>          Components: build
>    Affects Versions: 3.0.0-alpha2
>            Reporter: Sean Mackrory
>            Assignee: Sean Mackrory
>         Attachments: HADOOP-13659.001.patch
>
>
> We're currently pulling in version 2.2.2 - I think we should upgrade to the 
> latest 2.2.12.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to