Kiran Velumuri created ATLAS-4997: ------------------------------------- Summary: commons-collections dependency on atlas-intg 2.4.0 Key: ATLAS-4997 URL: https://issues.apache.org/jira/browse/ATLAS-4997 Project: Atlas Issue Type: Improvement Affects Versions: 2.4.0 Reporter: Kiran Velumuri
The artifact commons-collections:3.2.2, which is a dependency for [atlas-intg|https://mvnrepository.com/artifact/org.apache.atlas/atlas-intg/2.4.0], is EOL. Due to this, there are security vulnerabilities for commons-collections:3.2.2. The latest atlas-intg release 2.4.0 contains the vulunerable commons-collections:3.2.2. The non vulnerable version of commons-collections is [commons-collections4|https://mvnrepository.com/artifact/org.apache.commons/commons-collections4]. This issue is track when the new release of atlas-intg would not contain the vulnerable commons-collections:3.2.2. -- This message was sent by Atlassian Jira (v8.20.10#820010)