[Security/Dependency] Bump org.apache.ranger:ranger-plugins-common to 2.4.0+ in juicefs-hadoop to resolve CVE-2022-45048 #7341
Unanswered
smittal8-at
asked this question in
Q&A
Replies: 1 comment
|
ok. This issue is being tracked to ensure its completion. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What happened?
Our Software Composition Analysis (SCA) scanners are flagging the
io.juicefs:juicefs-hadoopdependency because it pulls in a vulnerable version of Apache Ranger plugins (org.apache.ranger:ranger-plugins-common:2.3.0).Apache Ranger 2.3.0 contains known high-severity vulnerabilities, most notably:
What is the expected behavior?
The Ranger dependencies in the
juicefs-hadoopSDK should be bumped to a secure version. The Apache Software Foundation has resolved these vulnerabilities in Apache Ranger 2.4.0 and newer.Could the maintainers please update the
ranger.versionproperty (or equivalent) for the Hadoop SDK to2.4.0or2.5.0in an upcoming release to clear these security flags?Additional Context
juicefs/sdk/java(JuiceFS Hadoop Java SDK)org.apache.ranger:ranger-plugins-common:2.3.02.4.0or2.5.0All reactions