[
https://issues.apache.org/jira/browse/HADOOP-14100?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Steve Loughran updated HADOOP-14100:
------------------------------------
Status: Patch Available (was: Reopened)
> Upgrade Jsch jar to latest version to fix vulnerability in old versions
> -----------------------------------------------------------------------
>
> Key: HADOOP-14100
> URL: https://issues.apache.org/jira/browse/HADOOP-14100
> Project: Hadoop Common
> Issue Type: Bug
> Affects Versions: 2.6.5, 2.7.3
> Reporter: Vinayakumar B
> Assignee: Vinayakumar B
> Priority: Critical
> Labels: release-blocker
> Fix For: 2.9.0, 2.8.1, 3.0.0-alpha3
>
> Attachments: HADOOP-14100-01.patch, HADOOP-14100-branch-2.7.patch
>
>
> Recently there was on vulnerability reported on jsch library. Its fixed in
> latest 0.1.54 version before CVE was made public.
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5725
> So, need to upgrade jsch to latest 0.1.54 version.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]