tanishqchugh created HIVE-28682:
-----------------------------------
Summary: Multiple Avro Versions on Classpath Can Cause Potential
Conflicts
Key: HIVE-28682
URL: https://issues.apache.org/jira/browse/HIVE-28682
Project: Hive
Issue Type: Bug
Components: Hive
Reporter: tanishqchugh
Assignee: tanishqchugh
Currently, there are 4 instances of Avro v1.7.7 jars coming in transitively
from hadoop-common. This can cause potential classpath conflicts in dynamic
class-loading with classes coming in from Avro v1.11.4 jars.
In addition, Avro v1.7.7 is affected with CVE-2024-47561 and CVE-2023-39410.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)