hadoop-common-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Steve Loughran (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HADOOP-15299) Bump Hadoop's Jackson 2 dependency 2.9.x
Date Fri, 09 Mar 2018 10:17:00 GMT

    [ https://issues.apache.org/jira/browse/HADOOP-15299?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16392669#comment-16392669

Steve Loughran commented on HADOOP-15299:

I agree on the need for this, but also fear it. 

I think we need to make sure that all client dependencies can be picked up shading, where
the cloud storage JARs come next. There's also 1+ JAR used by spark, plus what hive wants.

If we can do this, we can then do protobuf

> Bump Hadoop's Jackson 2 dependency 2.9.x
> ----------------------------------------
>                 Key: HADOOP-15299
>                 URL: https://issues.apache.org/jira/browse/HADOOP-15299
>             Project: Hadoop Common
>          Issue Type: Bug
>    Affects Versions: 3.1.0, 3.2.0
>            Reporter: Sean Mackrory
>            Assignee: Sean Mackrory
>            Priority: Major
> There are a few new CVEs open against Jackson 2.7.x. It doesn't (necessarily) mean Hadoop
is vulnerable to the attack - I don't know that it is, but fixes were released for Jackson
2.8.x and 2.9.x but not 2.7.x (which we're on). We shouldn't be on an unmaintained line, regardless.
HBase is already on 2.9.x, we have a shaded client now, the API changes are relatively minor
and so far in my testing I haven't seen any problems. I think many of our usual reasons to
hesitate upgrading this dependency don't apply.

This message was sent by Atlassian JIRA

To unsubscribe, e-mail: common-issues-unsubscribe@hadoop.apache.org
For additional commands, e-mail: common-issues-help@hadoop.apache.org

View raw message