Security Vulnerability - Action Required: “Loop with Unreachable Exit Condition ('Infinite Loop')” vulnerability in org.apache.zeppelin:zeppelin-scio_2.11 before the version of 0.8.2

2023-09-21 Thread James Watt
Hi there, I think the method io.netty.handler.ssl.OpenSslEngine.wrap(ByteBuffer[] srcs, int offset, int length, ByteBuffer dst) may have an “Loop with Unreachable Exit Condition ('Infinite Loop')” vulnerability which is vulnerable in org.apache.zeppelin:zeppelin-scio_2.11 before the version o

Security Vulnerability - Action Required: “Incorrect Permission Assignment for Critical Resource” vulnerability in org.apache.zeppelin:zeppelin-spark-dependencies-2.10 before 2.7.3

2023-09-21 Thread James Watt
Hi there, I think the method `org.apache.hadoop.mapreduce.filecache.ClientDistributedCacheManager.checkPermissionOfOther(FileSystem fs, Path path, FsAction action, Map statCache)` may have an “Incorrect Permission Assignment for Critical Resource”vulnerability which is vulnerable in org.apache