[
https://issues.apache.org/jira/browse/HADOOP-14100?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Arpit Agarwal updated HADOOP-14100:
-----------------------------------
Resolution: Fixed
Hadoop Flags: Reviewed
Fix Version/s: 3.0.0-alpha3
2.9.0
Target Version/s: (was: 2.9.0, 3.0.0-alpha3)
Status: Resolved (was: Patch Available)
Pushed to trunk, branch-2 and branch-2.8.
> Upgrade Jsch jar to latest version to fix vulnerability in old versions
> -----------------------------------------------------------------------
>
> Key: HADOOP-14100
> URL: https://issues.apache.org/jira/browse/HADOOP-14100
> Project: Hadoop Common
> Issue Type: Bug
> Affects Versions: 2.7.3, 2.6.5
> Reporter: Vinayakumar B
> Assignee: Vinayakumar B
> Priority: Critical
> Fix For: 2.9.0, 3.0.0-alpha3
>
> Attachments: HADOOP-14100-01.patch
>
>
> Recently there was on vulnerability reported on jsch library. Its fixed in
> latest 0.1.54 version before CVE was made public.
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5725
> So, need to upgrade jsch to latest 0.1.54 version.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]