[ 
https://issues.apache.org/jira/browse/FLINK-28798?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Martijn Visser closed FLINK-28798.
----------------------------------
    Resolution: Done

> Upgrade JDOM version to 2.0.6.1 in order to resolve CVE-2021-33813 
> -------------------------------------------------------------------
>
>                 Key: FLINK-28798
>                 URL: https://issues.apache.org/jira/browse/FLINK-28798
>             Project: Flink
>          Issue Type: Bug
>          Components: FileSystems
>    Affects Versions: 1.13.6
>            Reporter: Bilna
>            Priority: Major
>
> The flink-oss-fs-hadoop 
> module(flink/flink-filesystems/flink-oss-fs-hadoop/pom.xml) has 
> aliyun-sdk-oss:3.4.1 as dependency. The version of jdom in 
> aliyun-sdk-oss:3.4.1 is 1.1 which is vulnerable. The aliyun-sdk-oss:3.14.1 
> has jdom:2.0.6.1. Even the flink:1.15 has aliyun-sdk-oss:3.4.1 only.  Please 
> upgrade  aliyun-sdk-oss to 3.14.1



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to