Re: Hadoop depencency CVEs

2023-03-21 Thread Michiel de Jong
Hello, Thank you for setting us on the right path. We will use the 3.3.5 progress in our scanning. We are now familiarizing ourselves with the codebase and the encountered CVEs. Michiel de Jong email signature * Winner of Dutch Innovation award within Law Enforcement * Active in 30+ count

Re: Hadoop depencency CVEs

2023-03-14 Thread Steve Loughran
hello. welcome to the hadoop CVE support team! all this stuff happens on apache JIRA; the search term is project in (HADOOP, YARN, HDFS, MAPREDUCE) AND text ~ cve ORDER BY created DESC And we are cutting the 3.3.5 RC3 today; I just need to do the preflight checks before sending the emails. in th

Hadoop depencency CVEs

2023-03-14 Thread Michiel de Jong
Hello Hadoop Developers, When running a dependency cve scan on our project we noticed a list of dependencies in hadoop common that have some CVE. There are also several CVEs listed on https://mvnrepository.com/artifact/org.apache.hadoop/hadoop-common/3.3.4. Many of these CVEs would probably no