[ 
https://issues.apache.org/jira/browse/SPARK-35054?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17332436#comment-17332436
 ] 

Shashank Jain commented on SPARK-35054:
---------------------------------------

Hi [~srowen] as i said i saw it first with open jdk but even using open jdk 
docker without any critical vulnerability still spark docker was giving this 
vulnerability, so thats why asking here...in general also asking while creating 
spark docker are we running trivy scan on that ? and if yes then did we run in 
recent times for 3.0 release of spark without any critical vulnerability ?

> Getting Critical Vulnerability CVE-2021-20231 on spark 3.0.0 branch
> -------------------------------------------------------------------
>
>                 Key: SPARK-35054
>                 URL: https://issues.apache.org/jira/browse/SPARK-35054
>             Project: Spark
>          Issue Type: Bug
>          Components: Spark Core
>    Affects Versions: 3.0.0
>            Reporter: Shashank Jain
>            Priority: Major
>
> Currently while running Trivy Scan on Spark build we are getting the 
> following critical vulnerability 
> CVE-2021-20231   
> CVE-2021-20232
> How to fix these vulnerabilities in spark 3.0.0 branch ?



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to