[ https://issues.apache.org/jira/browse/HADOOP-18198?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Steve Loughran resolved HADOOP-18198. ------------------------------------- Fix Version/s: 3.3.3 Resolution: Fixed done! > Release Hadoop 3.3.3: hadoop-3.3.2 with some fixes > -------------------------------------------------- > > Key: HADOOP-18198 > URL: https://issues.apache.org/jira/browse/HADOOP-18198 > Project: Hadoop Common > Issue Type: Task > Components: build > Affects Versions: 3.3.2 > Reporter: Steve Loughran > Assignee: Steve Loughran > Priority: Major > Labels: pull-request-available > Fix For: 3.3.3 > > Time Spent: 2h 10m > Remaining Estimate: 0h > > Hadoop 3.3.3 is a minor followup release to Hadoop 3.3.2 with all the > incremental changes which went in to the 3.2.4 release > * minor CVE fixes in Hadoop source > * CVE fixes in dependencies we know of (protobuf unmarshalling leading to > DoS, jackson stack overflow,...) > * replacement of log4j 1.2.17 to reload4j > * node.js update > This is not a release off branch-3.3, it is a fork of 3.3.2 with the changes. > The next release of branch-3.3 will be numbered hadoop-3.3.4; updating maven > versions and JIRA fix versions is part of this release process. > The changes here are already in branch 3.2.4; this completes the set > CVEs fixed > * CVE-2022-26612: Apache Hadoop: Arbitrary file write in > FileUtil#unpackEntries on Windows (HADOOP-18155) -- This message was sent by Atlassian Jira (v8.20.7#820007) --------------------------------------------------------------------- To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-dev-h...@hadoop.apache.org