[ https://issues.apache.org/jira/browse/OOZIE-3653?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17888186#comment-17888186 ]
halim kim commented on OOZIE-3653: ---------------------------------- seems to need to upgrade again, 2.11 version has Direct Vulnerabilities too. * https://mvnrepository.com/artifact/commons-io/commons-io/2.11.0 * [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47554] pls consider upgrade to 2.14 or above. thank you. > Upgrade commons-io to 2.11.0 > ---------------------------- > > Key: OOZIE-3653 > URL: https://issues.apache.org/jira/browse/OOZIE-3653 > Project: Oozie > Issue Type: Improvement > Affects Versions: 5.2.1 > Reporter: Ashutosh Gupta > Assignee: Ashutosh Gupta > Priority: Major > Fix For: 5.3.0 > > Attachments: OOZIE-3653-001.patch, OOZIE-3653-002.patch > > > Current commons-io is using 2.4 which has the following vulnerabilities > Direct vulnerabilities: > [CVE-2021-29425|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29425] > Vulnerabilities from dependencies: > [CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250] > > We can upgrade to 2.8.0 -- This message was sent by Atlassian Jira (v8.20.10#820010)