[
https://issues.apache.org/jira/browse/HBASE-29840?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18053011#comment-18053011
]
Dávid Paksy commented on HBASE-29840:
-------------------------------------
Dependabot also created an automated PR to fix this:
https://github.com/apache/hbase/pull/7640
> Bump tar from 7.5.2 to 7.5.3 in /hbase-website
> ----------------------------------------------
>
> Key: HBASE-29840
> URL: https://issues.apache.org/jira/browse/HBASE-29840
> Project: HBase
> Issue Type: Task
> Components: website
> Reporter: Dávid Paksy
> Assignee: Dávid Paksy
> Priority: Major
>
> Dependabot reported a new high security vulnerability in node-tar:
> node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via
> Insufficient Path Sanitization
> [https://github.com/apache/hbase/security/dependabot/123]
>
> node-tar is a dependency in hbase-website.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)