There is a vulnerability in Apache Hadoop 2.7.4 ,upgrade recommended
Open
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 306
- Forks
- 75
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/linkedin/transport/blob/92dfbbfd989367418bdd14f9ac4cc2bcf1e7c777/transportable-udfs-hive/build.gradle#L7
CVE-2017-15718 CVE-2018-8009 CVE-2020-9492 CVE-2018-11766 CVE-2018-8029
Recommended upgrade version:
2.10.1
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review transportable-udfs-hive/build.gradle at line 7 and compare the Apache Hadoop dependency with the listed CVEs and recommended version 2.10.1. Update the dependency if the project remains compatible, then verify that the build completes without dependency-resolution or compilation errors.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- hadoop, java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 55/100