There is a vulnerability in Apache Hadoop 2.8.5,upgrade recommended
Open
Area - Dependencies
Security
- Dominant language
- Java
- Stars
- 14.1k
- Forks
- 3.8k
- Avg merge
- 1d 19h
- Merged PRs (30d)
- 209
Description
https://github.com/apache/druid/blob/52d46cebc31026b8dd39c7d9fb82c62bd77965fb/pom.xml#L109
CVE-2018-11765
Recommended upgrade version:2.10.0
Contributor guide
Research direction
Open pom.xml at line 109 and inspect the Hadoop 2.8.5 dependency associated with CVE-2018-11765. Update the dependency to the recommended 2.10.0 version and verify that the project still resolves the dependency successfully.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- hadoop, java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100