Re: Security Vulnerability - Action Required: “Incorrect Permission Assignment for Critical Resource” vulnerability in org.apache.zeppelin:zeppelin-spark-dependencies-2.10 before 2.7.3

2023-09-27 Thread Jongyoul Lee
Hello, Thank you for reporting it. By the way, we won't release spark-2.10 from the next release and you don't have to worry about it. Best regards, Jongyoul 2023년 9월 21일 (목) 오후 9:57, James Watt 님이 작성: > Hi there, > I think the method >

Security Vulnerability - Action Required: “Incorrect Permission Assignment for Critical Resource” vulnerability in org.apache.zeppelin:zeppelin-spark-dependencies-2.10 before 2.7.3

2023-09-21 Thread James Watt
Hi there, I think the method `org.apache.hadoop.mapreduce.filecache.ClientDistributedCacheManager.checkPermissionOfOther(FileSystem fs, Path path, FsAction action, Map statCache)` may have an “Incorrect Permission Assignment for Critical Resource”vulnerability which is vulnerable in