[
https://issues.apache.org/jira/browse/HDFS-17826?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Alexander Veit updated HDFS-17826:
----------------------------------
Description:
com.nimbusds:nimbus-jose-jwt:9.37.2 (from Dec 2023) which is included in the
Apache Hadoop Client Runtime 3.4.2 is affected by CVE-2025-53864 (Score 5.8).
[https://nvd.nist.gov/vuln/detail/CVE-2025-53864]
Possible solution: Update to com.nimbusds:nimbus-jose-jwt:9.37.4 or higher.
was:
com.nimbusds:nimbus-jose-jwt:9.37.2 (from Dec 2023) which is included in the
Apache Hadoop Client Runtime 3.4.2 is affected by CVE-2025-53864 (Score 5.8).
[https://nvd.nist.gov/vuln/detail/CVE-2025-53864]
> hadoop-client-runtime vulnerabilitiy from nimbus-jose-jwt 9.37.2
> ----------------------------------------------------------------
>
> Key: HDFS-17826
> URL: https://issues.apache.org/jira/browse/HDFS-17826
> Project: Hadoop HDFS
> Issue Type: Bug
> Affects Versions: 3.4.2
> Reporter: Alexander Veit
> Priority: Major
>
> com.nimbusds:nimbus-jose-jwt:9.37.2 (from Dec 2023) which is included in the
> Apache Hadoop Client Runtime 3.4.2 is affected by CVE-2025-53864 (Score 5.8).
> [https://nvd.nist.gov/vuln/detail/CVE-2025-53864]
> Possible solution: Update to com.nimbusds:nimbus-jose-jwt:9.37.4 or higher.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]