[ 
https://issues.apache.org/jira/browse/SPARK-38061?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17486791#comment-17486791
 ] 

Sujit Biswas commented on SPARK-38061:
--------------------------------------

 

*htrace-core4-4.1.0-incubating.jar* is about jackson-databind, not sure you are 
able to understand the issue, see the results, example below 

 

*CRITICAL,* "Vulnerability found in non-os package type (java) *- 
/opt/spark/jars/htrace-core4-4.1.0-incubating.jar:jackson-databind* (fixed in: 
2.9.10)(GHSA-f3j5-rmmp-3fc5 - 
[https://github.com/advisories/GHSA-f3j5-rmmp-3fc5] 
)","GHSA-f3j5-rmmp-3fc5+htrace-core4-4.1.0-incubating.jar:jackson-databind",package,vulnerabilities,

 

> security scan issue jackson-databinding HDFS dependency library
> ---------------------------------------------------------------
>
>                 Key: SPARK-38061
>                 URL: https://issues.apache.org/jira/browse/SPARK-38061
>             Project: Spark
>          Issue Type: Bug
>          Components: Kubernetes, Security
>    Affects Versions: 3.2.0
>            Reporter: Sujit Biswas
>            Priority: Major
>         Attachments: image-2022-02-03-08-02-29-071.png, 
> scan-security-report-spark-3.2.0-jre-11.csv, 
> scan-security-report-spark-3.2.1-jre-11.csv
>
>
> Hi,
> running into security scan issue with docker image built on 
> spark-3.2.0-bin-hadoop3.2, is there a way to resolve 
>  
> most issues related to https://issues.apache.org/jira/browse/HDFS-15333 
> attaching the CVE report
>  



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org
For additional commands, e-mail: issues-h...@spark.apache.org

Reply via email to