Uploaded image for project: 'Hive'
  1. Hive
  2. HIVE-22374

Upgrade commons-compress version to 1.19

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • None
    • 4.0.0-alpha-1
    • Hive
    • None

    Description

      As described in CVE-2019-12402, commons-compress:1.18 has an issue where certain inputs may cause an infinite loop which leads to a denial of service attack.

      This patch simply upgrades common-compress versions from 1.18 to 1.19 which is the latest minor version at the date of filing this issue (Maven repo).

      Attachments

        1. HIVE-22374.1.patch
          0.6 kB
          Sumin Byeon
        2. HIVE-22374.2.patch
          0.6 kB
          Sumin Byeon

        Activity

          People

            shortbread Sumin Byeon
            shortbread Sumin Byeon
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: