Re: CVE-2020-13936

2022-05-05 Thread Martin Grigorov
Hi, On Thu, May 5, 2022 at 8:44 PM Sean Owen wrote: > This is a Velocity issue. Spark doesn't use it, although it looks like > Avro does. From reading the CVE, I do not believe it would impact Avro's > usage - velocity templates it may use for codegen aren't exposed that I > know of. Is there a

Re: CVE-2020-13936

2022-05-05 Thread Sean Owen
This is a Velocity issue. Spark doesn't use it, although it looks like Avro does. From reading the CVE, I do not believe it would impact Avro's usage - velocity templates it may use for codegen aren't exposed that I know of. Is there a known relationship to Spark here? That is the key question in

CVE-2020-13936

2022-05-05 Thread Pralabh Kumar
Hi Dev Team Please let me know if there is a jira to track this CVE changes with respect to Spark . Searched jira but couldn't find anything. Please help Regards Pralabh Kumar