RE: CVE-2022-42889

2022-10-27 Thread Deepti Sharma S
Thank you for sharing the link, however when is the plan to release version 3.3.5 which has the fix of this CVE? Regards, Deepti Sharma PMP® & ITIL From: Wei-Chiu Chuang Sent: 27 October 2022 21:21 Cc: user@hadoop.apache.org Subject: Re: CVE-2022-42889 1. HADOOP-18497&l

Re: CVE-2022-42889

2022-10-27 Thread Wei-Chiu Chuang
1. HADOOP-18497 <https://issues.apache.org/jira/browse/HADOOP-18497> On Thu, Oct 27, 2022 at 4:45 AM Deepti Sharma S wrote: > Hello Team, > > > > As we have received the vulnerability “CVE-2022-42889”. We are using > Apache Hadoop common 3pp version 3.3.3 which h

CVE-2022-42889

2022-10-27 Thread Deepti Sharma S
Hello Team, As we have received the vulnerability "CVE-2022-42889". We are using Apache Hadoop common 3pp version 3.3.3 which has transitive dependency of Common text. Do you have any plans to fix this vulnerability in Hadoop next version and when is the plan? Regards, Deepti Sh