[ https://issues.apache.org/jira/browse/SPARK-38061?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17486791#comment-17486791 ]
Sujit Biswas commented on SPARK-38061: -------------------------------------- *htrace-core4-4.1.0-incubating.jar* is about jackson-databind, not sure you are able to understand the issue, see the results, example below *CRITICAL,* "Vulnerability found in non-os package type (java) *- /opt/spark/jars/htrace-core4-4.1.0-incubating.jar:jackson-databind* (fixed in: 2.9.10)(GHSA-f3j5-rmmp-3fc5 - [https://github.com/advisories/GHSA-f3j5-rmmp-3fc5] )","GHSA-f3j5-rmmp-3fc5+htrace-core4-4.1.0-incubating.jar:jackson-databind",package,vulnerabilities, > security scan issue jackson-databinding HDFS dependency library > --------------------------------------------------------------- > > Key: SPARK-38061 > URL: https://issues.apache.org/jira/browse/SPARK-38061 > Project: Spark > Issue Type: Bug > Components: Kubernetes, Security > Affects Versions: 3.2.0 > Reporter: Sujit Biswas > Priority: Major > Attachments: image-2022-02-03-08-02-29-071.png, > scan-security-report-spark-3.2.0-jre-11.csv, > scan-security-report-spark-3.2.1-jre-11.csv > > > Hi, > running into security scan issue with docker image built on > spark-3.2.0-bin-hadoop3.2, is there a way to resolve > > most issues related to https://issues.apache.org/jira/browse/HDFS-15333 > attaching the CVE report > -- This message was sent by Atlassian Jira (v8.20.1#820001) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org For additional commands, e-mail: issues-h...@spark.apache.org