Kiran Velumuri created ATLAS-4997:
-------------------------------------

             Summary: commons-collections dependency on atlas-intg 2.4.0
                 Key: ATLAS-4997
                 URL: https://issues.apache.org/jira/browse/ATLAS-4997
             Project: Atlas
          Issue Type: Improvement
    Affects Versions: 2.4.0
            Reporter: Kiran Velumuri


The artifact commons-collections:3.2.2, which is a dependency for 
[atlas-intg|https://mvnrepository.com/artifact/org.apache.atlas/atlas-intg/2.4.0],
 is EOL. Due to this, there are security vulnerabilities for 
commons-collections:3.2.2. 

The latest atlas-intg release 2.4.0 contains the vulunerable 
commons-collections:3.2.2. The non vulnerable version of commons-collections is 
[commons-collections4|https://mvnrepository.com/artifact/org.apache.commons/commons-collections4].

This issue is track when the new release of atlas-intg would not contain the 
vulnerable commons-collections:3.2.2.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to