Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve reported CVEs #15081

Merged
merged 1 commit into from
Oct 4, 2023
Merged

Conversation

tejaswini-imply
Copy link
Member

  1. Suppressed CVE-2022-4244 which is wrongly matched on org.codehaus.plexus:plexus-interpolation artifact.
  2. Updated snappy-java to 1.1.10.4 to address CVE-2023-43642.
  3. Suppressed CVE-2023-39410 which is a legitimate vulnerability of the Avro library but there isn't a fix available in the Hadoop repo yet.

@abhishekagarwal87 abhishekagarwal87 merged commit 28870c7 into apache:master Oct 4, 2023
29 checks passed
@LakshSingla LakshSingla added this to the 28.0 milestone Oct 12, 2023
ektravel pushed a commit to ektravel/druid that referenced this pull request Oct 16, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants