[
https://issues.apache.org/jira/browse/HIVE-28682?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated HIVE-28682:
----------------------------------
Labels: pull-request-available (was: )
> Multiple Avro Versions on Classpath Can Cause Potential Conflicts
> -----------------------------------------------------------------
>
> Key: HIVE-28682
> URL: https://issues.apache.org/jira/browse/HIVE-28682
> Project: Hive
> Issue Type: Bug
> Components: Hive
> Reporter: tanishqchugh
> Assignee: tanishqchugh
> Priority: Major
> Labels: pull-request-available
>
> Currently, there are 4 instances of Avro v1.7.7 jars coming in transitively
> from hadoop-common. This can cause potential classpath conflicts in dynamic
> class-loading with classes coming in from Avro v1.11.4 jars.
> In addition, Avro v1.7.7 is affected with CVE-2024-47561 and CVE-2023-39410.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)