[ https://issues.apache.org/jira/browse/HIVE-25726 ]
John Tal deleted comment on HIVE-25726: --------------------------------- was (Author: JIRAUSER303766): [~ngangam] [~sourabh912] - Can someone please describe where this fix was made? We are stuck on 1.7 for various reasons and need to know how you addressed this so we can potentially backport a fix to a 1.7 fork. I looked at the PRs in github but they show dependency changes, not java changes. Thank you. > Upgrade velocity to 2.3 due to CVE-2020-13936 > --------------------------------------------- > > Key: HIVE-25726 > URL: https://issues.apache.org/jira/browse/HIVE-25726 > Project: Hive > Issue Type: Task > Reporter: Sourabh Goyal > Assignee: Sourabh Goyal > Priority: Major > Labels: pull-request-available, release-3.1.3 > Fix For: 4.0.0-alpha-1 > > Time Spent: 1h 20m > Remaining Estimate: 0h > > Velocity project announced CVE-2020-13936 on 20210309 and through NVD > 20210317 to get detected internally. > * [https://nvd.nist.gov/vuln/detail/CVE-2020-13936] > * [http://velocity.apache.org/news.html] -- This message was sent by Atlassian Jira (v8.20.10#820010)