[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-12 Thread kirby zhou (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17521228#comment-17521228 ] kirby zhou commented on RANGER-3691: For me, if 2.3.0 will release before June, it is acceptable. If

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-12 Thread Christian Pfarr (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17521038#comment-17521038 ] Christian Pfarr commented on RANGER-3691: - [~rmani] if this is fixed in 2.3, maybe you could

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-12 Thread Christian Pfarr (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17521034#comment-17521034 ] Christian Pfarr commented on RANGER-3691: - Hi [~rmani], for me it doesnt matter if there is a

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-11 Thread Ramesh Mani (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17520784#comment-17520784 ] Ramesh Mani commented on RANGER-3691: - [~kirbyzhou]  [~z0ltrix]  could you please provide your

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-08 Thread Ramesh Mani (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17519673#comment-17519673 ] Ramesh Mani commented on RANGER-3691: - [~kirbyzhou]  since this CVE

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-08 Thread kirby zhou (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17519414#comment-17519414 ] kirby zhou commented on RANGER-3691: Way 1:  migrate from log4j to slf4j/logback log system I think

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-07 Thread Ramesh Mani (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17519090#comment-17519090 ] Ramesh Mani commented on RANGER-3691: - [~kirbyzhou]  could you please refer the log4j-logback

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-07 Thread Christian Pfarr (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17518678#comment-17518678 ] Christian Pfarr commented on RANGER-3691: - yes please... i´ve done this as well with 2.2.0 after

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-06 Thread kirby zhou (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17518551#comment-17518551 ] kirby zhou commented on RANGER-3691: If 2.2.1, log4j-logback patches should also be picked. >

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-06 Thread Christian Pfarr (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17518176#comment-17518176 ] Christian Pfarr commented on RANGER-3691: - Hey guys, would it be possible to create a 2.2.1

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-04 Thread Pradeep Agrawal (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17517200#comment-17517200 ] Pradeep Agrawal commented on RANGER-3691: - [~kirbyzhou]  : Please close the RR :

[jira] [Commented] (RANGER-3691) Upgrade spring to 5.3.18 CVE-2022-22965

2022-04-01 Thread kirby zhou (Jira)
[ https://issues.apache.org/jira/browse/RANGER-3691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17515849#comment-17515849 ] kirby zhou commented on RANGER-3691: [https://reviews.apache.org/r/73924]/ > Upgrade spring to