[ 
https://issues.apache.org/jira/browse/OOZIE-3653?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Ashutosh Gupta updated OOZIE-3653:
----------------------------------
    Description: 
Current commons-io is using 2.4 which has the following vulnerabilities

Direct vulnerabilities:
[CVE-2021-29425|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29425]

Vulnerabilities from dependencies:
[CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]

 

We can upgrade to `2.8.0`

  was:
Current commons-io is using `2.4` which has the following vulnerabilities

Direct vulnerabilities:
[CVE-2021-29425|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29425]

Vulnerabilities from dependencies:
[CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]

 

We can upgrade to `2.8.0`


> Upgrade commons-io to 2.8.0
> ---------------------------
>
>                 Key: OOZIE-3653
>                 URL: https://issues.apache.org/jira/browse/OOZIE-3653
>             Project: Oozie
>          Issue Type: Bug
>            Reporter: Ashutosh Gupta
>            Priority: Major
>
> Current commons-io is using 2.4 which has the following vulnerabilities
> Direct vulnerabilities:
> [CVE-2021-29425|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29425]
> Vulnerabilities from dependencies:
> [CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]
>  
> We can upgrade to `2.8.0`



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to