Skip to content

Conversation

@vtutrinov
Copy link
Contributor

What changes were proposed in this pull request?

Resolve the CVEs:

https://nvd.nist.gov/vuln/detail/CVE-2023-34453
https://nvd.nist.gov/vuln/detail/CVE-2023-34454
https://nvd.nist.gov/vuln/detail/CVE-2023-34455

Please describe your PR in detail:
An old version of snappy-java lib was replaced with a new one

https://issues.apache.org/jira/browse/HDDS-10459

How was this patch tested?

repo's robot tests

Copy link
Contributor

@adoroszlai adoroszlai left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @vtutrinov for the patch.

@adoroszlai adoroszlai changed the title HDDS-10459. replace snappy-java:1.1.8.2 with snappy-java:1.1.10.5 for hadoop-common (CVE fix) HDDS-10459. Bump snappy-java to 1.1.10.5 for hadoop-common (CVE fix) Mar 4, 2024
@adoroszlai adoroszlai merged commit 650e777 into apache:master Mar 4, 2024
@adoroszlai
Copy link
Contributor

Thanks @vtutrinov for updating the patch.

adoroszlai pushed a commit to adoroszlai/ozone that referenced this pull request Mar 5, 2024
jojochuang pushed a commit to jojochuang/ozone that referenced this pull request Mar 15, 2024
Fixes:

- CVE-2023-34453
- CVE-2023-34454
- CVE-2023-34455

(cherry picked from commit 650e777)
Change-Id: I9ef43a5224c7dd36c13d9032fd9a8de481716612
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants