Skip to content

Patched security vulnerability by updating Ranger libraries to the ne…#15363

Merged
abhishekagarwal87 merged 5 commits into
apache:masterfrom
vivek807:feature-ranger-extension-vulnerability-fix
Nov 22, 2023
Merged

Patched security vulnerability by updating Ranger libraries to the ne…#15363
abhishekagarwal87 merged 5 commits into
apache:masterfrom
vivek807:feature-ranger-extension-vulnerability-fix

Conversation

@vivek807

Copy link
Copy Markdown
Contributor

Fixes #14454 .

Description

Patched security vulnerability by updating Ranger libraries to the newest available version.

Release note

This change removes the log4j dependency from the extension. It is done by updating Ranger libraries to the newest available version. The functioning of this library does not change.


@BartMiki BartMiki left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There were no changes to the Druid parent pom.xml, the ranger version should be updated there.

Comment thread extensions-core/druid-ranger-security/pom.xml Outdated
Comment thread extensions-core/druid-ranger-security/pom.xml Outdated
Comment thread extensions-core/druid-ranger-security/pom.xml Outdated
Comment thread extensions-core/druid-ranger-security/pom.xml Outdated
Comment thread extensions-core/druid-ranger-security/src/assembly/assembly.xml Outdated
@vivek807
vivek807 marked this pull request as ready for review November 15, 2023 12:50

@cryptoe cryptoe left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes LGTM. Waiting for a clean CI run.

@abhishekagarwal87
abhishekagarwal87 merged commit c14cfc2 into apache:master Nov 22, 2023
@abhishekagarwal87

Copy link
Copy Markdown
Contributor

thank you for your first contribution @vivek807

@vivek807

Copy link
Copy Markdown
Contributor Author

thank you for your first contribution @vivek807

Thanks @abhishekagarwal87 :)

yashdeep97 pushed a commit to yashdeep97/druid that referenced this pull request Dec 1, 2023
apache#15363)

Patched security vulnerability by updating Ranger libraries to the newest available version.
Pankaj260100 pushed a commit to confluentinc/druid that referenced this pull request Dec 13, 2023
apache#15363)

Patched security vulnerability by updating Ranger libraries to the newest available version.
Pankaj260100 pushed a commit to confluentinc/druid that referenced this pull request Dec 19, 2023
apache#15363)

Patched security vulnerability by updating Ranger libraries to the newest available version.
Pankaj260100 pushed a commit to confluentinc/druid that referenced this pull request Dec 19, 2023
apache#15363)

Patched security vulnerability by updating Ranger libraries to the newest available version.
@LakshSingla LakshSingla added this to the 29.0.0 milestone Jan 29, 2024
LakshSingla added a commit to LakshSingla/druid that referenced this pull request Feb 12, 2024
riovic918data pushed a commit to riovic918data/druid that referenced this pull request Jun 12, 2026
apache#15363)

Patched security vulnerability by updating Ranger libraries to the newest available version.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vulnerable Log4j 1.x is bundled with the Ranger extension

5 participants