From 178bbe79eec705cb942093af3d84d4a96e8838e8 Mon Sep 17 00:00:00 2001 From: Ashutosh Gupta Date: Thu, 8 Sep 2022 20:39:08 +0100 Subject: [PATCH 1/2] HADOOP-18443. Upgrade snakeyaml to 1.31 to mitigate CVE-2022-25857 --- hadoop-project/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hadoop-project/pom.xml b/hadoop-project/pom.xml index 1c2eae6dbb684..45e6a6c7d96ba 100644 --- a/hadoop-project/pom.xml +++ b/hadoop-project/pom.xml @@ -182,7 +182,7 @@ ${hadoop.version} 1.5.4 - 1.26 + 1.31 1.4.8 2.0.2 4.13.2 From f0df9ae21e1ec1a4fab1d83d66d18f658eddfa6f Mon Sep 17 00:00:00 2001 From: Ashutosh Gupta Date: Mon, 19 Sep 2022 02:17:06 +0100 Subject: [PATCH 2/2] upgrade snakeyaml to 1.32 --- hadoop-project/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hadoop-project/pom.xml b/hadoop-project/pom.xml index 45e6a6c7d96ba..a1e9ecb8756d3 100644 --- a/hadoop-project/pom.xml +++ b/hadoop-project/pom.xml @@ -182,7 +182,7 @@ ${hadoop.version} 1.5.4 - 1.31 + 1.32 1.4.8 2.0.2 4.13.2