-
Couldn't load subscription status.
- Fork 9.1k
HADOOP-17649. Update wildfly openssl to 2.2.1.Final #4539
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: trunk
Are you sure you want to change the base?
Conversation
|
|
💔 -1 overall
This message was automatically generated. |
|
@steveloughran - I saw your comments on this PR - #3029 about running the integration tests for
Let me know if you have any comments for this upgrade. |
|
@steveloughran - Can you please help with review this PR? Thanks. |
|
sort out some azure creds. good to play with the opposition anyway |
|
also, be good to know what linux version you are testing on. i will have to test this on a vm before merging too, because the openssl native integration has been brittle in the past |
|
I am testing this on: |
|
ok. i will do an (ec2) linux run later. that or fix my pi400 up for testing, which might be fun anyway |
|
catching up on this. its' too late for 3.3.5, but we can get it into branch-3.3. for the successor. can you rebase? |
Hi @steveloughran , sorry got busy with other few important stuff earlier. I will rebase it. Thanks for reminder. |
@steveloughran , I have rebased. Please help in review. |
|
💔 -1 overall
This message was automatically generated. |
|
revisting this. we need
|
Description of PR
Update wildfly openssl to 2.2.1.Final.
https://nvd.nist.gov/vuln/detail/CVE-2020-25644
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
JIRA - HADOOP-17649
How was this patch tested?
CI/Build.
After setting this property
Added test results for hadoop-aws integration tests
For code changes:
LICENSE,LICENSE-binary,NOTICE-binaryfiles?