[jira] [Comment Edited] (SPARK-38061) security scan issue jackson-databinding HDFS dependency library

2022-02-02 Thread Sujit Biswas (Jira)


[ 
https://issues.apache.org/jira/browse/SPARK-38061?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17486268#comment-17486268
 ] 

Sujit Biswas edited comment on SPARK-38061 at 2/3/22, 7:49 AM:
---

also if some of the issues are resolved, how to get the build that has the 
fixes, are the jackson-databind and log4j issue fixed in [Spark 
3.2.1|https://spark.apache.org/releases/spark-release-3-2-1.html]


was (Author: JIRAUSER284395):
also if some of the issues are resolved, how to get the build that has the fixes

> security scan issue jackson-databinding HDFS dependency library
> ---
>
> Key: SPARK-38061
> URL: https://issues.apache.org/jira/browse/SPARK-38061
> Project: Spark
>  Issue Type: Bug
>  Components: Kubernetes, Security
>Affects Versions: 3.2.0
>Reporter: Sujit Biswas
>Priority: Major
> Attachments: scan-security-report-spark-3.2.0-jre-11.csv
>
>
> Hi,
> running into security scan issue with docker image built on 
> spark-3.2.0-bin-hadoop3.2, is there a way to resolve 
>  
> most issues related to https://issues.apache.org/jira/browse/HDFS-15333 
> attaching the CVE report
>  



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

-
To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org
For additional commands, e-mail: issues-h...@spark.apache.org



[jira] [Comment Edited] (SPARK-38061) security scan issue jackson-databinding HDFS dependency library

2022-01-29 Thread Hyukjin Kwon (Jira)


[ 
https://issues.apache.org/jira/browse/SPARK-38061?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17484280#comment-17484280
 ] 

Hyukjin Kwon edited comment on SPARK-38061 at 1/30/22, 1:22 AM:


[~sujitbiswas], so do you propose to upgrade Jackson version? and which of them 
directly affect Spark?


was (Author: hyukjin.kwon):
[~sujitbiswas], so do you propose to upgrade Jackson version?

> security scan issue jackson-databinding HDFS dependency library
> ---
>
> Key: SPARK-38061
> URL: https://issues.apache.org/jira/browse/SPARK-38061
> Project: Spark
>  Issue Type: Bug
>  Components: Kubernetes, Security
>Affects Versions: 3.2.0
>Reporter: Sujit Biswas
>Priority: Major
> Attachments: scan-security-report-spark-3.2.0-jre-11.csv
>
>
> Hi,
> running into security scan issue with docker image built on 
> spark-3.2.0-bin-hadoop3.2, is there a way to resolve 
>  
> most issues related to https://issues.apache.org/jira/browse/HDFS-15333 
> attaching the CVE report
>  



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

-
To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org
For additional commands, e-mail: issues-h...@spark.apache.org