[ https://issues.apache.org/jira/browse/HADOOP-18492?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17617029#comment-17617029 ]
ASF GitHub Bot commented on HADOOP-18492: ----------------------------------------- ashutoshcipher commented on PR #5007: URL: https://github.com/apache/hadoop/pull/5007#issuecomment-1277563527 > @ashutoshcipher CI build seems to have run ok Yeah, Looks good. I > upgrade commons-text to 1.10.0 > ------------------------------ > > Key: HADOOP-18492 > URL: https://issues.apache.org/jira/browse/HADOOP-18492 > Project: Hadoop Common > Issue Type: Improvement > Reporter: PJ Fanning > Assignee: PJ Fanning > Priority: Major > Labels: pull-request-available > > Extends HADOOP-18341 > [https://commons.apache.org/proper/commons-text/changes-report.html#a1.10.0] > StringInterpolator prior to v1.10.0 allowed scripting that could be > problematic – a similar issue to one that led to CVE in > commons-configuration2. -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-issues-h...@hadoop.apache.org