[
https://issues.apache.org/jira/browse/HADOOP-19632?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18016098#comment-18016098
]
ASF GitHub Bot commented on HADOOP-19632:
-----------------------------------------
pjfanning commented on code in PR #7870:
URL: https://github.com/apache/hadoop/pull/7870#discussion_r2299121430
##########
hadoop-project/pom.xml:
##########
@@ -244,7 +244,7 @@
<openssl-wildfly.version>2.1.4.Final</openssl-wildfly.version>
<jsonschema2pojo.version>1.0.2</jsonschema2pojo.version>
<woodstox.version>5.4.0</woodstox.version>
- <nimbus-jose-jwt.version>9.37.2</nimbus-jose-jwt.version>
+ <nimbus-jose-jwt.version>9.37.4</nimbus-jose-jwt.version>
Review Comment:
@ayushtkn 9.48 is affected by CVE-2025-53864 while 9.37.4 was specifically
patched with the fix.
> Upgrade nimbusds to 10.0.2
> --------------------------
>
> Key: HADOOP-19632
> URL: https://issues.apache.org/jira/browse/HADOOP-19632
> Project: Hadoop Common
> Issue Type: Improvement
> Affects Versions: 3.4.1
> Reporter: Ananya Singh
> Assignee: Ananya Singh
> Priority: Major
> Labels: pull-request-available
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]