[
https://issues.apache.org/jira/browse/OOZIE-3653?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17488905#comment-17488905
]
ASF subversion and git services commented on OOZIE-3653:
--------------------------------------------------------
Commit e1ee62df147d6ca4a71b4189fb048c68b0e1e464 in oozie's branch
refs/heads/master from Denes Bodo
[ https://gitbox.apache.org/repos/asf?p=oozie.git;h=e1ee62d ]
OOZIE-3653 Upgrade commons-io to 2.11.0 (groot via dionusos)
> Upgrade commons-io to 2.11.0
> ----------------------------
>
> Key: OOZIE-3653
> URL: https://issues.apache.org/jira/browse/OOZIE-3653
> Project: Oozie
> Issue Type: Improvement
> Affects Versions: 5.2.1
> Reporter: Ashutosh Gupta
> Assignee: Ashutosh Gupta
> Priority: Major
> Attachments: OOZIE-3653-001.patch, OOZIE-3653-002.patch
>
>
> Current commons-io is using 2.4 which has the following vulnerabilities
> Direct vulnerabilities:
> [CVE-2021-29425|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29425]
> Vulnerabilities from dependencies:
> [CVE-2020-15250|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15250]
>
> We can upgrade to 2.8.0
--
This message was sent by Atlassian Jira
(v8.20.1#820001)