Re: [PR] CVE-2023-2976 [hadoop-thirdparty]

2024-01-16 Thread via GitHub
saeidN commented on PR #25: URL: https://github.com/apache/hadoop-thirdparty/pull/25#issuecomment-1894687524 Sorry to post here but I couldn't find this info anywhere else. When will maven repo be updated? It still has old version which was last updated in 2021: -- This is an automated

Re: [PR] CVE-2023-2976 [hadoop-thirdparty]

2023-10-19 Thread via GitHub
Grimoren commented on PR #25: URL: https://github.com/apache/hadoop-thirdparty/pull/25#issuecomment-1771425717 @coheigea @goiri Is it possible to merge either this or #23 ? It looks like the checks have passed on both of them (unless there is some other check we are waiting for?) -- Th

Re: [PR] CVE-2023-2976 [hadoop-thirdparty]

2023-10-18 Thread via GitHub
Grimoren commented on PR #25: URL: https://github.com/apache/hadoop-thirdparty/pull/25#issuecomment-1769675664 > Note we already have a JIRA and PR #23 for this CVE Yeah I saw that. I just want to see someone merge the fix. Either way, as long as the cve is patched. I will close this

Re: [PR] CVE-2023-2976 [hadoop-thirdparty]

2023-10-17 Thread via GitHub
coheigea commented on PR #25: URL: https://github.com/apache/hadoop-thirdparty/pull/25#issuecomment-1767618510 Note we already have a JIRA and PR https://github.com/apache/hadoop-thirdparty/pull/23 for this CVE -- This is an automated message from the Apache Git Service. To respond to the

Re: [PR] CVE-2023-2976 [hadoop-thirdparty]

2023-10-17 Thread via GitHub
goiri commented on PR #25: URL: https://github.com/apache/hadoop-thirdparty/pull/25#issuecomment-1767154645 Approved but waiting for the CI run. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to th

[PR] CVE-2023-2976 [hadoop-thirdparty]

2023-10-17 Thread via GitHub
Grimoren opened a new pull request, #25: URL: https://github.com/apache/hadoop-thirdparty/pull/25 Published Vulnerabilities CVE-2023-2976 Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems a