Kiran Velumuri created ATLAS-4997:
-------------------------------------
Summary: commons-collections dependency on atlas-intg 2.4.0
Key: ATLAS-4997
URL: https://issues.apache.org/jira/browse/ATLAS-4997
Project: Atlas
Issue Type: Improvement
Affects Versions: 2.4.0
Reporter: Kiran Velumuri
The artifact commons-collections:3.2.2, which is a dependency for
[atlas-intg|https://mvnrepository.com/artifact/org.apache.atlas/atlas-intg/2.4.0],
is EOL. Due to this, there are security vulnerabilities for
commons-collections:3.2.2.
The latest atlas-intg release 2.4.0 contains the vulunerable
commons-collections:3.2.2. The non vulnerable version of commons-collections is
[commons-collections4|https://mvnrepository.com/artifact/org.apache.commons/commons-collections4].
This issue is track when the new release of atlas-intg would not contain the
vulnerable commons-collections:3.2.2.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)