[ 
https://issues.apache.org/jira/browse/SPARK-33734?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17248747#comment-17248747
 ] 

Hyukjin Kwon commented on SPARK-33734:
--------------------------------------

Which security issue do you refer then?

> Spark Core ::Spark core versions upto 3.0.1 using interdependency on 
> Jackson-core-asl version 1.9.13, which is having security issues reported. 
> ------------------------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: SPARK-33734
>                 URL: https://issues.apache.org/jira/browse/SPARK-33734
>             Project: Spark
>          Issue Type: Bug
>          Components: Spark Core
>    Affects Versions: 3.0.1
>            Reporter: Aparna
>            Priority: Major
>
> spark-core version upto latest 3.0.1 is using dependency 
> [org.apache.avro|https://mvnrepository.com/artifact/org.apache.avro] version 
> 1.8.2 which is having 
> [jackson-core-asl|https://mvnrepository.com/artifact/org.codehaus.jackson/jackson-core-asl]
>  version 1.9.13 which has security issues.
> Please fix and share the new version.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org
For additional commands, e-mail: issues-h...@spark.apache.org

Reply via email to