Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-17683

Update commons-io to 2.8.0

    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      https://nvd.nist.gov/vuln/detail/CVE-2021-29425

      In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

      We don't use this API in the Hadoop code, but it's still good to update anyway (we're on 2.5, which is 4 years old)

      Attachments

        Issue Links

          Activity

            People

              aajisaka Akira Ajisaka
              weichiu Wei-Chiu Chuang
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 40m
                  40m