[
https://issues.apache.org/jira/browse/SPARK-28255?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16880218#comment-16880218
]
Bozhidar Bozhanov commented on SPARK-28255:
-------------------------------------------
[~hyukjin.kwon] yes, upgrade the dependency to a non-vulnerable version. It
would be a bad idea to ship a vulnerable version and leave users to actually
detect the vulnerability and override the depnednency.
In that sense, I don't think the issue is invalid.
> Upgrade dependencies with vulnerabilities
> -----------------------------------------
>
> Key: SPARK-28255
> URL: https://issues.apache.org/jira/browse/SPARK-28255
> Project: Spark
> Issue Type: Bug
> Components: Spark Core
> Affects Versions: 3.0.0
> Reporter: Bozhidar Bozhanov
> Priority: Major
>
> There are severe vulnerabilities in two dependencies:
>
> [ERROR] hadoop-mapreduce-client-core-2.7.3.jar: CVE-2018-8029,
> CVE-2016-6811[ERROR] py4j-0.10.8.1.jar: CVE-2016-5636, CVE-2008-1887
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]