Fixed CVEs
Common Vulnerabilities and Exposures (CVE) that are addressed in this release are mentioned in the following table:
Ambari
CVEs fixed in the Spring Security library
CVE-2022-22978, CVE-2021-22112, CVE-2021-22060, CVE-2022-22970, CVE-2022-22971, WS-2020-0293, CVE-2023-20863, CVE-2022-22950, CVE-2021-22096, CVE-2022-22968, CVE-2021-22096, WS-2016-7107, CVE-2023-20861, CVE-2021-22096, CVE-2021-22096
Upgraded the following CVEs in the Apache Commons library
CVE-2021-35517, CVE-2021-36090, CVE-2021-35515, CVE-2019-12402, CVE-2021-35516, CVE-2021-29425,
CVEs fixed in the Apache Ant library
CVE-2020-11979, CVE-2021-36374, CVE-2021-36373, CVE-2020-1945
CVEs fixed in Apache HttpClient library
WS-2017-3734, CVE-2020-13956, CVE-2020-13956
CVEs fixed in Bootstrap JavaScript library
CVE-2018-14042
Hadoop
CVEs fixed in Jetty library
CVE-2023-36478, CVE-2021-34429, CVE-2023-26048, CVE-2021-28169, CVE-2021-28169, CVE-2023-26049, CVE-2021-34429, CVE-2023-26049, CVE-2021-34429, CVE-2023-40167, WS-2023-0236, CVE-2022-2047, CVE-2022-2047, CVE-2021-34428
CVEs fixed in Netty library
CVE-2019-20444, CVE-2023-4586, WS-2020-0408, CVE-2023-34462, CVE-2021-43797, CVE-2022-24823, CVE-2023-34462
CVEs fixed in SnakeYAML Java library
CVE-2022-1471, CVE-2022-25857, CVE-2022-41854, CVE-2022-38752, CVE-2022-38750, CVE-2022-38749, CVE-2022-38751
CVEs fixed in Gson Java library
CVE-2022-25647, WS-2021-0419
CVEs fixed in Google Guava library
CVE-2023-2976, CVE-2020-8908
CVEs fixed in Snappy library
CVE-2023-43642, CVE-2023-34455, CVE-2023-34453, CVE-2023-34454
CVE fixed in Woodstox library
CVE-2022-40152
HBase
CVEs fixed in Hadoop library
CVE-2022-25168, CVE-2022-26612, CVE-2020-9492, CVE-2021-33036, CVE-2021-25642, CVE-2020-9492
CVEs fixed in Nimbus Jose + JWT Java library
CVE-2019-17195
CVEs fixed in Woodstox library
WS-2018-0629, CVE-2022-40152
CVEs fixed in Google Guava library
CVE-2023-2976, CVE-2018-10237
CVEs fixed in Gson Java library
WS-2021-0419, CVE-2022-25647
CVEs fixed in Snappy library
CVE-2023-34455, CVE-2023-34454, CVE-2023-34453, CVE-2023-43642
Upgraded the following CVEs in the Apache Commons library
CVE-2021-35516, CVE-2021-36090, CVE-2021-35517, CVE-2021-35515
CVEs fixed in Jersey Core library
CVE-2014-3643
Hive
CVEs fixed in SnakeYAML Java library
CVE-2022-1471
CVEs fixed in Apache Ivy library
CVE-2022-37865, CVE-2022-37865
CVEs fixed in PostgreSQL library
CVE-2022-26520, WS-2022-0080, CVE-2022-21724
CVEs fixed in cron-utils Java library
CVE-2021-41269
CVEs fixed in Google OAuth Client library
CVE-2020-7692
CVEs fixed in Netty library
CVE-2019-20444, CVE-2023-4586, WS-2020-0408, CVE-2022-41881, CVE-2023-34462, CVE-2023-34462, CVE-2021-43797, CVE-2022-24823, CVE-2023-34462, CVE-2021-21295, CVE-2021-21290, CVE-2021-43797
CVEs fixed in Apache Maven Shared Utils library
CVE-2022-29599
CVEs fixed in HyperSQL Database Java library
CVE-2022-41853
CVEs fixed in Snappy library
CVE-2023-43642, CVE-2023-34453, CVE-2023-34454, CVE-2023-34455, CVE-2023-34453, CVE-2023-43642, CVE-2023-34455, CVE-2023-34454
CVEs fixed in Apache Avro library
CVE-2023-39410, CVE-2023-39410
Hue
CVEs fixed in Django Python framework
CVE-2016-9013, CVE-2022-28347, CVE-2022-28346, CVE-2022-34265, CVE-2021-35042, CVE-2023-31047, CVE-2019-19844, CVE-2022-34265
CVEs fixed in Pycrypto Python library
CVE-2013-7459
CVEs fixed in tough-cookie library
CVE-2023-26136
CVEs fixed in json-schema-library
CVE-2021-3918
CVEs fixed in Minimist JavaScript library
CVE-2021-44906, CVE-2021-44906
CVEs fixed in ini library
CVE-2020-7788
CVEs fixed in certifi package
CVE-2023-37920
Livy
CVEs fixed in Hadoop library
CVE-2022-25168, CVE-2022-26612, CVE-2022-25168, CVE-2022-26612, CVE-2017-15718
CVEs fixed in Netty library
CVE-2019-20444, CVE-2019-20444
CVEs fixed in Apache Zookeeper library
CVE-2023-44981
NiFi
CVEs fixed in SnakeYAML library
CVE-2022-1471
CVEs fixed in Hadoop library
CVE-2022-25168, CVE-2022-26612, CVE-2022-25168, CVE-2022-26612, CVE-2022-25168, CVE-2022-26612, CVE-2016-3086, CVE-2022-25168, CVE-2022-26612
CVEs fixed in Nimbus JOSE+JWT library
CVE-2019-17195, CVE-2019-17195
CVEs fixed in Apache Ivy library
CVE-2022-37865, CVE-2022-37865
CVEs fixed in Woodstox library
WS-2018-0629
CVEs fixed in Jackson JSON Processor library
CVE-2019-10202, CVE-2019-10202
CVEs fixed in the Spring Security library
CVE-2016-1000027, CVE-2023-34034, CVE-2023-20873
CVEs fixed in Hazelcast library
CVE-2022-36437
CVEs fixed in H2 Database Engine library
CVE-2021-23463, CVE-2021-42392, CVE-2022-23221
CVEs fixed in Apache Commons Collections library
CVE-2015-7501, CVE-2017-15708, CVE-2019-13116
CVEs fixed in Apache Hive JDBC Driver library
CVE-2018-1282, CVE-2018-1282
CVEs fixed in Apache Zookeeper library
CVE-2023-44981, CVE-2023-44981
Ranger
CVEs fixed in Netty library
CVE-2019-20444, CVE-2023-4586, CVE-2021-37137, WS-2020-0408, CVE-2021-37136, WS-2020-0408, CVE-2023-4586, WS-2020-0408, CVE-2023-4586, CVE-2021-37136, CVE-2021-37137, WS-2020-0408, CVE-2022-41881, CVE-2021-43797, CVE-2023-34462 ,CVE-2022-24823, CVE-2023-34462, CVE-2023-34462, CVE-2021-43797, CVE-2022-24823, CVE-2022-24823, CVE-2023-34462, CVE-2022-24823, CVE-2023-34462, CVE-2021-21290, CVE-2023-34462
CVEs fixed in SnakeYAML library
CVE-2022-1471, CVE-2017-18640, CVE-2022-25857, CVE-2022-38751, CVE-2022-38749, CVE-2022-41854, CVE-2022-38752, CVE-2022-38750
CVEs fixed in Nimbus JOSE+JWT library
CVE-2019-17195
CVEs fixed in Hadoop library
CVE-2022-25168, CVE-2022-26612, CVE-2020-9492, CVE-2020-9492
CVEs fixed in Woodstox library
WS-2018-0629, CVE-2022-40152, CVE-2022-40152, CVE-2022-40152
CVEs fixed in Apache Commons Collections library
CVE-2022-42889, CVE-2021-35516, CVE-2021-35515, CVE-2021-36090, CVE-2021-35517, CVE-2021-35516, CVE-2021-36090, CVE-2021-35517, CVE-2021-35515, WS-2019-0379, WS-2019-0379, CVE-2018-11771
CVEs fixed in Apache Ivy library
CVE-2022-37865
CVEs fixed in the Spring Security library
CVE-2022-31692, CVE-2023-34034, CVE-2022-22978, CVE-2022-22968, CVE-2023-20861, CVE-2022-22970, CVE-2023-20863, CVE-2022-22970
CVEs fixed in Handlebars library
CVE-2021-23383, CVE-2021-23369
CVEs fixed in Apache Zookeeper library
CVE-2023-44981, CVE-2023-44981
CVEs fixed in Elasticsearch library
CVE-2020-7014, CVE-2020-7021, CVE-2021-22134, CVE-2020-7020
CVEs fixed in Jersey library
CVE-2014-3643, CVE-2014-3643
Spark 3
CVEs fixed in Apache Ivy library
CVE-2022-37865
CVEs fixed in Apache Commons Collections library
CVE-2022-42889
CVEs fixed in Apache Spark library
CVE-2023-22946, CVE-2023-22946
Tez
CVEs fixed in Snappy library
CVE-2023-34453, CVE-2023-34455, CVE-2023-43642, CVE-2023-34454
CVEs fixed in Netty library
CVE-2023-4586, WS-2020-0408, CVE-2023-4586, CVE-2023-34462, CVE-2023-34462, CVE-2021-21290, CVE-2023-34462
CVEs fixed in Gson Java library
CVE-2022-25647, WS-2021-0419
CVEs fixed in Google Guava library
CVE-2023-2976
CVEs fixed in Jetty library
CVE-2021-34429, CVE-2023-26049, CVE-2021-34429, CVE-2021-34429, CVE-2023-26048, CVE-2021-28169, CVE-2023-26049, CVE-2021-28169, CVE-2023-40167
Zeppelin
CVEs fixed in Apache Zeppelin library
CVE-2019-10095
CVEs fixed in Lodash library
CVE-2019-10744
CVEs fixed in Minimist JavaScript library
CVE-2021-44906
CVEs fixed in Kramdown library
CVE-2020-14001
Zookeeper
CVEs fixed in Apache Zookeeper library
CVE-2023-44981
CVEs fixed in Netty library
CVE-2023-4586, CVE-2023-34462

Have a suggestion?