[ https://issues.apache.org/jira/browse/HIVE-27012?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Devaspati Krishnatri resolved HIVE-27012. ----------------------------------------- Fix Version/s: 4.0.0 Resolution: Fixed > Remove JavaEWAH dependency from HIVE to fix CVEs. > ------------------------------------------------- > > Key: HIVE-27012 > URL: https://issues.apache.org/jira/browse/HIVE-27012 > Project: Hive > Issue Type: Task > Reporter: Devaspati Krishnatri > Assignee: Devaspati Krishnatri > Priority: Major > Labels: pull-request-available > Fix For: 4.0.0 > > Attachments: tree.txt > > Time Spent: 1.5h > Remaining Estimate: 0h > > Upgrade JavaEWAH to 1.1.7 > JavaEWAH:0.3.2 is pulling in CVE-2022-29580. > CVE-2022-29580 is a High Severity CVE with CVSSv3 Score 7.8 -- This message was sent by Atlassian Jira (v8.20.10#820010)