Skip to content

[Snyk] Security upgrade org.apache.hive:hive-exec from 2.3.7 to 4.1.0 - #260

Open
chncaption wants to merge 1 commit into
masterfrom
snyk-fix-0f33d2acebee8d70ee560425e409ee22
Open

[Snyk] Security upgrade org.apache.hive:hive-exec from 2.3.7 to 4.1.0#260
chncaption wants to merge 1 commit into
masterfrom
snyk-fix-0f33d2acebee8d70ee560425e409ee22

Conversation

@chncaption

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 35 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • fe/pom.xml

Vulnerabilities that will be fixed with an upgrade:

IssueScoreUpgrade
critical severityDeserialization of Untrusted Data
SNYK-JAVA-LOG4J-572732
715org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundProof of Concept
medium severityDenial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426
670org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeReachableProof of Concept
critical severityImproper Input Validation
SNYK-JAVA-ORGCODEHAUSJACKSON-3326362
640org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severitySQL Injection
SNYK-JAVA-LOG4J-2342645
630org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundProof of Concept
high severityUncontrolled Recursion
SNYK-JAVA-COMMONSLANG-10734077
590org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityStack-based Buffer Overflow
SNYK-JAVA-COMFASTERXMLJACKSONCORE-10500754
585org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityDenial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538
585org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityStack-based Buffer Overflow
SNYK-JAVA-COMGOOGLEPROTOBUF-8055227
585org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityArbitrary Code Execution
SNYK-JAVA-LOG4J-2316893
555org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundProof of Concept
high severityDeserialization of Untrusted Data
SNYK-JAVA-LOG4J-2342646
555org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityDeserialization of Untrusted Data
SNYK-JAVA-LOG4J-2342647
555org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityInfinite loop
SNYK-JAVA-ORGAPACHECOMMONS-6254296
555org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityDirectory Traversal
SNYK-JAVA-COMMONSIO-1277109
535org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundMature
high severityDenial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
525org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityDenial of Service (DoS)
SNYK-JAVA-COMGOOGLEPROTOBUF-2331703
525org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityDenial of Service (DoS)
SNYK-JAVA-COMGOOGLEPROTOBUF-3167772
525org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityInformation Exposure
SNYK-JAVA-IONETTY-30430
525org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityDenial of Service (DoS)
SNYK-JAVA-ORGAPACHECOMMONS-1316641
525org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
high severityXML External Entity (XXE) Injection
SNYK-JAVA-ORGCODEHAUSJACKSON-534878
525org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424
520org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundProof of Concept
medium severityUncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JAVA-COMMONSIO-8161190
495org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityXML External Entity (XXE) Injection
SNYK-JAVA-COMSUNJERSEY-10441493
495org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
low severityInformation Exposure
SNYK-JAVA-COMMONSCODEC-561518
485org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeReachableNo Known Exploit
medium severityInformation Exposure
SNYK-JAVA-COMFASTERXMLJACKSONCORE-10332631
480org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundProof of Concept
medium severityDenial of Service (DoS)
SNYK-JAVA-ORGAPACHECOMMONS-1316638
475org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-ORGAPACHECOMMONS-1316639
475org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-ORGAPACHECOMMONS-1316640
475org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-2326698
445org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-LOG4J-3358774
445org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-COMGOOGLEPROTOBUF-3040284
435org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-ORGAPACHECOMMONS-32473
425org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
medium severityCross-site Request Forgery (CSRF)
SNYK-JAVA-ORGAPACHEHADOOP-31587
415org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
low severityInformation Disclosure
SNYK-JAVA-COMGOOGLEGUAVA-1015415
390org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundProof of Concept
low severityMan-in-the-Middle (MitM)
SNYK-JAVA-LOG4J-1300176
335org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit
low severityCreation of Temporary File in Directory with Insecure Permissions
SNYK-JAVA-COMGOOGLEGUAVA-5710356
315org.apache.hive:hive-exec:
2.3.7 -> 4.1.0
Major version upgradeNo Path FoundNo Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Information Exposure
🦉 Denial of Service (DoS)
🦉 Information Disclosure
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-LOG4J-572732
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426
- https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSJACKSON-3326362
- https://snyk.io/vuln/SNYK-JAVA-LOG4J-2342645
- https://snyk.io/vuln/SNYK-JAVA-COMMONSLANG-10734077
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-10500754
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEPROTOBUF-8055227
- https://snyk.io/vuln/SNYK-JAVA-LOG4J-2316893
- https://snyk.io/vuln/SNYK-JAVA-LOG4J-2342646
- https://snyk.io/vuln/SNYK-JAVA-LOG4J-2342647
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-6254296
- https://snyk.io/vuln/SNYK-JAVA-COMMONSIO-1277109
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEPROTOBUF-2331703
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEPROTOBUF-3167772
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-30430
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-1316641
- https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSJACKSON-534878
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424
- https://snyk.io/vuln/SNYK-JAVA-COMMONSIO-8161190
- https://snyk.io/vuln/SNYK-JAVA-COMSUNJERSEY-10441493
- https://snyk.io/vuln/SNYK-JAVA-COMMONSCODEC-561518
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-10332631
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-1316638
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-1316639
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-1316640
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-2326698
- https://snyk.io/vuln/SNYK-JAVA-LOG4J-3358774
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEPROTOBUF-3040284
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-32473
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEHADOOP-31587
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415
- https://snyk.io/vuln/SNYK-JAVA-LOG4J-1300176
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-5710356
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chncaption@snyk-bot