Skip to content

[FP]: Hadoop version (3.4.2) incorrectly identified as shaded dependency version (1.4.0) #8223

@rogermortas

Description

@rogermortas

Package URl

pkg:maven/org.apache.hadoop.thirdparty/hadoop-shaded-protobuf_3_25@1.4.0

CPE

cpe:2.3:a:apache:hadoop:1.4.0:*:*:*:*:*:*:*

CVE

CVE-2022-26612

ODC Integration

{"label" => "Maven Plugin"}

ODC Version

12.1.9

Description

The dependency is part of hadoop-client-runtime-3.4.2: hadoop-client-runtime-3.4.2.jar (shaded: org.apache.hadoop.thirdparty:hadoop-shaded-protobuf_3_25:1.4.0)

This seems to be new behaviour since updating from ODC 12.1.8 to 12.1.9

There are also other CVEs reported but CVE-2022-26612 is CRITICAL (the others are HIGH or less) and the root cause of all seems to be the incorrect version

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions