devaspatikrishnatri opened a new pull request, #3643:
URL: https://github.com/apache/hive/pull/3643

   [HIVE-26594](https://issues.apache.org/jira/browse/HIVE-26594)
   Upgrade netty to 4.1.77 due to CVE-2022-24823
   
   Netty is an open-source, asynchronous event-driven network application 
framework. The package `io.netty:netty-codec-http` prior to version 
4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's 
multipart decoders are used local information disclosure can occur via the 
local system temporary directory if temporary storing uploads on the disk is 
enabled. This only impacts applications running on Java version 6 and lower. 
Additionally, this vulnerability impacts code running on Unix-like systems, and 
very old versions of Mac OSX and Windows as they all share the system temporary 
directory between all users. Version 4.1.77.Final contains a patch for this 
vulnerability. As a workaround, specify one's own `java.io.tmpdir` when 
starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the 
directory to something that is only readable by the current user.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to