[ https://issues.apache.org/jira/browse/HADOOP-15970?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Akira Ajisaka reassigned HADOOP-15970: -------------------------------------- Assignee: Akira Ajisaka > Update or remove plexus-utils > ----------------------------- > > Key: HADOOP-15970 > URL: https://issues.apache.org/jira/browse/HADOOP-15970 > Project: Hadoop Common > Issue Type: Bug > Components: security > Reporter: Akira Ajisaka > Assignee: Akira Ajisaka > Priority: Major > Attachments: HADOOP-15970.01.patch > > > Apache Hadoop uses plexus-utils 2.0.5 and it is vulnerable. > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000487 > Let's update the version or remove the usage of this library. -- This message was sent by Atlassian JIRA (v7.6.3#76005) --------------------------------------------------------------------- To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-issues-h...@hadoop.apache.org