[
https://issues.apache.org/jira/browse/FLUME-3403?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17475717#comment-17475717
]
ASF subversion and git services commented on FLUME-3403:
--------------------------------------------------------
Commit 3ae856b529a85bd5b88b078c9e4d5b405dca8287 in flume's branch
refs/heads/trunk from Ralph Goers
[ https://gitbox.apache.org/repos/asf?p=flume.git;h=3ae856b ]
FLUME-3403 - Remove the morphline-solr-sink since Kite is abandonded
> The parquet-avro version used by flume is 1.4.1, which is vulnerabel.
> ---------------------------------------------------------------------
>
> Key: FLUME-3403
> URL: https://issues.apache.org/jira/browse/FLUME-3403
> Project: Flume
> Issue Type: Improvement
> Components: Node
> Affects Versions: 1.9.0
> Reporter: zhou yong
> Priority: Blocker
> Fix For: notrack
>
>
> flume-ng-dist-1.9.0 requires the parquet-avro component, and the required
> version is as follows:
> <dependency>
> <groupId>com.twitter</groupId>
> <artifactId>parquet-avro</artifactId>
> <version>1.4.1</version>
> </dependency>
>
> The parquet-avro is maintained by apache from 1.6.0, but there are
> vulnerabilities with each version. There is also a vulnerability in
> parquet-avro version 1.4.1,as detailed : Improper Input Validation
> vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by
> malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0
> and later versions. [https://nvd.nist.gov/vuln/detail/CVE-2021-41561]
> Do you have any good solutions?
--
This message was sent by Atlassian Jira
(v8.20.1#820001)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]