[ 
https://issues.apache.org/jira/browse/SPARK-18997?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15777815#comment-15777815
 ] 

Liang-Chi Hsieh commented on SPARK-18997:
-----------------------------------------

I've checked the dependency and seems there is no conflict.

{code}
    +-org.apache.thrift:libfb303:0.9.3
    | +-org.apache.thrift:libthrift:0.9.3
    |   +-org.apache.httpcomponents:httpclient:4.4.1 (evicted by: 4.5.2)
    |   +-org.apache.httpcomponents:httpclient:4.5.2
    |   | +-commons-codec:commons-codec:1.10
    |   | +-commons-codec:commons-codec:1.9 (evicted by: 1.10)
    |   | +-commons-logging:commons-logging:1.2
    |   | +-org.apache.httpcomponents:httpcore:4.4.4
    |   |
    |   +-org.apache.httpcomponents:httpcore:4.4.1 (evicted by: 4.4.4)
    |   +-org.apache.httpcomponents:httpcore:4.4.4
    |
    +-org.apache.thrift:libthrift:0.9.3
    | +-org.apache.httpcomponents:httpclient:4.4.1 (evicted by: 4.5.2)
    | +-org.apache.httpcomponents:httpclient:4.5.2
    | | +-commons-codec:commons-codec:1.10
    | | +-commons-codec:commons-codec:1.9 (evicted by: 1.10)
    | | +-commons-logging:commons-logging:1.2
    | | +-org.apache.httpcomponents:httpcore:4.4.4
    | |
    | +-org.apache.httpcomponents:httpcore:4.4.1 (evicted by: 4.4.4)
    | +-org.apache.httpcomponents:httpcore:4.4.4
    |
{code}

[~srowen] What do you think about this? Do we want to upgrade this?

> Recommended upgrade libthrift  to 0.9.3
> ---------------------------------------
>
>                 Key: SPARK-18997
>                 URL: https://issues.apache.org/jira/browse/SPARK-18997
>             Project: Spark
>          Issue Type: Bug
>          Components: Build
>            Reporter: meiyoula
>            Priority: Critical
>
> libthrift 0.9.2 has a serious security vulnerability:CVE-2015-3254



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to