Skip to content

Commit 00db9a2

Browse files
MikaelSmithImpala Public Jenkins
authored andcommitted
IMPALA-11407: Upgrade google-oauth-client to 1.33.3
Upgrades google-oauth-client and google-oauth-client-java6 to 1.33.3 to address CVE-2021-22573. These are included as dependencies of com.google.cloud.bigdataoss/gcs-connector, which does not yet have a release that includes versions 1.33.3 or later. Change-Id: I8d95913f26e6073373374e169ee045881f40f065 Reviewed-on: http://gerrit.cloudera.org:8080/18683 Reviewed-by: Impala Public Jenkins <impala-public-jenkins@cloudera.com> Tested-by: Impala Public Jenkins <impala-public-jenkins@cloudera.com>
1 parent 9c96855 commit 00db9a2

2 files changed

Lines changed: 13 additions & 0 deletions

File tree

java/executor-deps/pom.xml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -138,6 +138,18 @@ under the License.
138138
<version>${gcs.version}</version>
139139
</dependency>
140140

141+
<!-- Dependency of gcs-connector, newer version addresses CVE -->
142+
<dependency>
143+
<groupId>com.google.oauth-client</groupId>
144+
<artifactId>google-oauth-client</artifactId>
145+
<version>${google.oauth-client.version}</version>
146+
</dependency>
147+
<dependency>
148+
<groupId>com.google.oauth-client</groupId>
149+
<artifactId>google-oauth-client-java6</artifactId>
150+
<version>${google.oauth-client.version}</version>
151+
</dependency>
152+
141153
<dependency>
142154
<groupId>com.qcloud.cos</groupId>
143155
<artifactId>hadoop-cos</artifactId>

java/pom.xml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,7 @@ under the License.
4646
<kite.version>${env.IMPALA_KITE_VERSION}</kite.version>
4747
<knox.version>${env.IMPALA_KNOX_VERSION}</knox.version>
4848
<gcs.version>${env.IMPALA_GCS_VERSION}</gcs.version>
49+
<google.oauth-client.version>1.33.3</google.oauth-client.version>
4950
<cos.version>${env.IMPALA_COS_VERSION}</cos.version>
5051
<thrift.version>${env.IMPALA_THRIFT_POM_VERSION}</thrift.version>
5152
<impala.extdatasrc.api.version>${project.version}</impala.extdatasrc.api.version>

0 commit comments

Comments
 (0)