[ https://issues.apache.org/jira/browse/FLINK-28798?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Martijn Visser closed FLINK-28798. ---------------------------------- Resolution: Done > Upgrade JDOM version to 2.0.6.1 in order to resolve CVE-2021-33813 > ------------------------------------------------------------------- > > Key: FLINK-28798 > URL: https://issues.apache.org/jira/browse/FLINK-28798 > Project: Flink > Issue Type: Bug > Components: FileSystems > Affects Versions: 1.13.6 > Reporter: Bilna > Priority: Major > > The flink-oss-fs-hadoop > module(flink/flink-filesystems/flink-oss-fs-hadoop/pom.xml) has > aliyun-sdk-oss:3.4.1 as dependency. The version of jdom in > aliyun-sdk-oss:3.4.1 is 1.1 which is vulnerable. The aliyun-sdk-oss:3.14.1 > has jdom:2.0.6.1. Even the flink:1.15 has aliyun-sdk-oss:3.4.1 only. Please > upgrade aliyun-sdk-oss to 3.14.1 -- This message was sent by Atlassian Jira (v8.20.10#820010)