[
https://issues.apache.org/jira/browse/HBASE-28410?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Work on HBASE-28410 started by Dávid Paksy.
-------------------------------------------
> Upgrade curator to 5.7.1
> ------------------------
>
> Key: HBASE-28410
> URL: https://issues.apache.org/jira/browse/HBASE-28410
> Project: HBase
> Issue Type: Improvement
> Components: Zookeeper
> Reporter: Istvan Toth
> Assignee: Dávid Paksy
> Priority: Minor
>
> HBase still uses Curator 4.2.0, -because it's the last version to support ZK
> 3.4.-
> Now that, with HBASE-28153, HBase uses a recent ZK, we can use the latest
> Curator.
> Also, curator 4.2.0 has multiple indirect vulnerabilities as per
> https://mvnrepository.com/artifact/org.apache.curator/curator-client/4.2.0
> Vulnerabilities from dependencies:
> * CVE-2023-44981
> * CVE-2023-2976
> * CVE-2022-4065
> * CVE-2020-8908
> * CVE-2019-0201
--
This message was sent by Atlassian Jira
(v8.20.10#820010)