[ https://issues.apache.org/jira/browse/SPARK-34618?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Sean R. Owen resolved SPARK-34618. ---------------------------------- Resolution: Duplicate > CVEs in library dependencies > ---------------------------- > > Key: SPARK-34618 > URL: https://issues.apache.org/jira/browse/SPARK-34618 > Project: Spark > Issue Type: Bug > Components: PySpark > Affects Versions: 3.1.1 > Reporter: Douglas Gerhardt > Priority: Major > > There are several CVEs in dependency libraries in the current version of > pyspark, including shaded ones under JARs such as > * htrace-core4-4.1.0-incubating.jar:jackson-databind > Are these already being looked at? If not, could they be updated to reference > newer versions? Thanks. > |CVE ID|Type|Severity|Packages|Package Version|CVSS|Fix Status| > |CVE-2017-18640|java|high|org.yaml_snakeyaml|1.24|7.5|fixed in 1.26| > |CVE-2020-25649|java|high|com.fasterxml.jackson.core_jackson-databind|2.10.0|7.5|fixed > in 2.10.5.1, 2.9.10.7, 2.6.7.4| > |CVE-2020-35491|java|high|com.fasterxml.jackson.core_jackson-databind|2.4.0|8.1|fixed > in 2.9.10.8| > |CVE-2020-35490|java|high|com.fasterxml.jackson.core_jackson-databind|2.4.0|8.1|fixed > in 2.9.10.8| > |CVE-2018-14718|java|critical|com.fasterxml.jackson.core_jackson-databind|2.4.0|9.8|fixed > in 2.9.7| > |CVE-2018-7489|java|critical|com.fasterxml.jackson.core_jackson-databind|2.4.0|9.8|fixed > in 2.9.5, 2.8.11.1, 2.7.9.3| > |CVE-2020-25649|java|high|com.fasterxml.jackson.core_jackson-databind|2.10.0|7.5|fixed > in 2.10.5.1, 2.9.10.7, 2.6.7.4| > |CVE-2020-35491|java|high|com.fasterxml.jackson.core_jackson-databind|2.4.0|8.1|fixed > in 2.9.10.8| > |CVE-2020-35490|java|high|com.fasterxml.jackson.core_jackson-databind|2.4.0|8.1|fixed > in 2.9.10.8| > |CVE-2018-14718|java|critical|com.fasterxml.jackson.core_jackson-databind|2.4.0|9.8|fixed > in 2.9.7| > |CVE-2018-7489|java|critical|com.fasterxml.jackson.core_jackson-databind|2.4.0|9.8|fixed > in 2.9.5, 2.8.11.1, 2.7.9.3| > |CVE-2017-18640|java|high|org.yaml_snakeyaml|1.24|7.5|fixed in 1.26| > |CVE-2020-25649|java|high|com.fasterxml.jackson.core_jackson-databind|2.10.0|7.5|fixed > in 2.10.5.1, 2.9.10.7, 2.6.7.4| > |CVE-2020-35491|java|high|com.fasterxml.jackson.core_jackson-databind|2.4.0|8.1|fixed > in 2.9.10.8| > |CVE-2020-35490|java|high|com.fasterxml.jackson.core_jackson-databind|2.4.0|8.1|fixed > in 2.9.10.8| > |CVE-2018-14718|java|critical|com.fasterxml.jackson.core_jackson-databind|2.4.0|9.8|fixed > in 2.9.7| > |CVE-2018-7489|java|critical|com.fasterxml.jackson.core_jackson-databind|2.4.0|9.8|fixed > in 2.9.5, 2.8.11.1, 2.7.9.3| > |CVE-2017-18640|java|high|org.yaml_snakeyaml|1.24|7.5|fixed in 1.26| > |CVE-2019-17195|java|critical|com.nimbusds_nimbus-jose-jwt|4.41.1|9.8|fixed > in 7.9| > > Similar issues, for reference: > # CAMEL-14640 > # HADOOP-16690 > # ZEPPELIN-4657 -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org For additional commands, e-mail: issues-h...@spark.apache.org