Yaniv Kunda created HADOOP-19578:
------------------------------------

             Summary: Upgrade com.huaweicloud:esdk-obs-java for CVE-2023-3635
                 Key: HADOOP-19578
                 URL: https://issues.apache.org/jira/browse/HADOOP-19578
             Project: Hadoop Common
          Issue Type: Improvement
          Components: cloud-storage, huaweicloud
    Affects Versions: 3.4.1, 3.3.6
            Reporter: Yaniv Kunda


The `com.huaweicloud:esdk-obs-java` dependency , used exclusively by the 
`hadoop-huaweicloud` uses `com.squareup.okio:okio:1.17.2` which has 
[CVE-2023-3635|https://nvd.nist.gov/vuln/detail/cve-2023-3635].
Upgrading it will use a newer fixed version of okio, which will mitigate the 
vulnerability.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org
For additional commands, e-mail: common-dev-h...@hadoop.apache.org

Reply via email to