[ 
https://issues.apache.org/jira/browse/HBASE-29840?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18053011#comment-18053011
 ] 

Dávid Paksy commented on HBASE-29840:
-------------------------------------

Dependabot also created an automated PR to fix this:

https://github.com/apache/hbase/pull/7640

> Bump tar from 7.5.2 to 7.5.3 in /hbase-website
> ----------------------------------------------
>
>                 Key: HBASE-29840
>                 URL: https://issues.apache.org/jira/browse/HBASE-29840
>             Project: HBase
>          Issue Type: Task
>          Components: website
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>
> Dependabot reported a new high security vulnerability in node-tar:
> node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via 
> Insufficient Path Sanitization
> [https://github.com/apache/hbase/security/dependabot/123]
>  
> node-tar is a dependency in hbase-website.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to