[ 
https://issues.apache.org/jira/browse/SPARK-28255?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16879802#comment-16879802
 ] 

Bozhidar Bozhanov commented on SPARK-28255:
-------------------------------------------

Hello,

 

The py4j might be a false positive, but the hadoop one is on the CVE list. 
Here's a list of hadoop vulnerabilities: 
[https://hadoop.apache.org/cve_list.html]

 

I'd recommend including this plugin that automatically checks for vulnerable 
dependencies (that's how I discovered them)

https://jeremylong.github.io/DependencyCheck/dependency-check-maven/

> Upgrade dependencies with vulnerabilities
> -----------------------------------------
>
>                 Key: SPARK-28255
>                 URL: https://issues.apache.org/jira/browse/SPARK-28255
>             Project: Spark
>          Issue Type: Bug
>          Components: Spark Core
>    Affects Versions: 3.0.0
>            Reporter: Bozhidar Bozhanov
>            Priority: Major
>
> There are severe vulnerabilities in two dependencies:
>  
> [ERROR] hadoop-mapreduce-client-core-2.7.3.jar: CVE-2018-8029, 
> CVE-2016-6811[ERROR] py4j-0.10.8.1.jar: CVE-2016-5636, CVE-2008-1887



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to