[ https://issues.apache.org/jira/browse/SPARK-34403?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17281180#comment-17281180 ]
Apache Spark commented on SPARK-34403: -------------------------------------- User 'ssainz' has created a pull request for this issue: https://github.com/apache/spark/pull/31528 > Remove dependency to commons-httpclient, is not used and has vulnerabilities. > ----------------------------------------------------------------------------- > > Key: SPARK-34403 > URL: https://issues.apache.org/jira/browse/SPARK-34403 > Project: Spark > Issue Type: Bug > Components: Spark Core > Affects Versions: 3.1.0 > Reporter: Sergio Sainz > Priority: Major > > <dependency> > <groupId>commons-httpclient</groupId> > <artifactId>commons-httpclient</artifactId> > </dependency> > > Has vulnerabilities as below: > > CVE-2012-6153 > CVE-2012-5783 > > Also, after removing it and running `spark/sql/hive$mvn compile test` the > result is SUCCESS > -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org For additional commands, e-mail: issues-h...@spark.apache.org