Uploaded image for project: 'HBase'
  1. HBase
  2. HBASE-28067

Hbase 2.4.13 vulnerable to CVE-2022-26612

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • 2.4.13
    • None
    • Client
    • None
    • Incompatible change

    Description

      hbase 2.4.13 uses hadoop-common-2.10.0.jar which is vulnerable to CVE-2022-26612.

      when replaced hadoop-common-2.10.0.jar with 3.2.3, getting version incompatible issue and as result hbase shell command failed.

      is there any hbase version which is compatible with hadoop-common 3.2.3 or above?

      or is there any hbase version available where the above CVE addressed?

       

      Attachments

        Activity

          People

            Unassigned Unassigned
            kmandal kaushik mandal
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: