diff --git a/LICENSE-binary b/LICENSE-binary index 499485263906a..c62da6f08abab 100644 --- a/LICENSE-binary +++ b/LICENSE-binary @@ -325,20 +325,20 @@ org.apache.solr:solr-solrj:8.8.2 org.apache.yetus:audience-annotations:0.5.0 org.apache.zookeeper:zookeeper:3.6.3 org.codehaus.jettison:jettison:1.1 -org.eclipse.jetty:jetty-annotations:9.4.44.v20210927 -org.eclipse.jetty:jetty-http:9.4.44.v20210927 -org.eclipse.jetty:jetty-io:9.4.44.v20210927 -org.eclipse.jetty:jetty-jndi:9.4.44.v20210927 -org.eclipse.jetty:jetty-plus:9.4.44.v20210927 -org.eclipse.jetty:jetty-security:9.4.44.v20210927 -org.eclipse.jetty:jetty-server:9.4.44.v20210927 -org.eclipse.jetty:jetty-servlet:9.4.44.v20210927 -org.eclipse.jetty:jetty-util:9.4.44.v20210927 -org.eclipse.jetty:jetty-util-ajax:9.4.44.v20210927 -org.eclipse.jetty:jetty-webapp:9.4.44.v20210927 -org.eclipse.jetty:jetty-xml:9.4.44.v20210927 -org.eclipse.jetty.websocket:javax-websocket-client-impl:9.4.44.v20210927 -org.eclipse.jetty.websocket:javax-websocket-server-impl:9.4.44.v20210927 +org.eclipse.jetty:jetty-annotations:9.4.48.v20220622 +org.eclipse.jetty:jetty-http:9.4.48.v20220622 +org.eclipse.jetty:jetty-io:9.4.48.v20220622 +org.eclipse.jetty:jetty-jndi:9.4.48.v20220622 +org.eclipse.jetty:jetty-plus:9.4.48.v20220622 +org.eclipse.jetty:jetty-security:9.4.48.v20220622 +org.eclipse.jetty:jetty-server:9.4.48.v20220622 +org.eclipse.jetty:jetty-servlet:9.4.48.v20220622 +org.eclipse.jetty:jetty-util:9.4.48.v20220622 +org.eclipse.jetty:jetty-util-ajax:9.4.48.v20220622 +org.eclipse.jetty:jetty-webapp:9.4.48.v20220622 +org.eclipse.jetty:jetty-xml:9.4.48.v20220622 +org.eclipse.jetty.websocket:javax-websocket-client-impl:9.4.48.v20220622 +org.eclipse.jetty.websocket:javax-websocket-server-impl:9.4.48.v20220622 org.ehcache:ehcache:3.3.1 org.lz4:lz4-java:1.7.1 org.objenesis:objenesis:2.6 diff --git a/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/http/HttpServer2.java b/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/http/HttpServer2.java index 2928f88598207..1db8c750cef93 100644 --- a/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/http/HttpServer2.java +++ b/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/http/HttpServer2.java @@ -97,7 +97,7 @@ import org.eclipse.jetty.server.Server; import org.eclipse.jetty.server.ServerConnector; import org.eclipse.jetty.server.SslConnectionFactory; -import org.eclipse.jetty.server.handler.AllowSymLinkAliasChecker; +import org.eclipse.jetty.server.SymlinkAllowedResourceAliasChecker; import org.eclipse.jetty.server.handler.ContextHandlerCollection; import org.eclipse.jetty.server.handler.HandlerCollection; import org.eclipse.jetty.server.handler.RequestLogHandler; @@ -939,7 +939,7 @@ protected void addDefaultApps(ContextHandlerCollection parent, handler.setHttpOnly(true); handler.getSessionCookieConfig().setSecure(true); logContext.setSessionHandler(handler); - logContext.addAliasCheck(new AllowSymLinkAliasChecker()); + logContext.addAliasCheck(new SymlinkAllowedResourceAliasChecker(logContext)); setContextAttributes(logContext, conf); addNoCacheFilter(logContext); defaultContexts.put(logContext, true); @@ -958,7 +958,7 @@ protected void addDefaultApps(ContextHandlerCollection parent, handler.setHttpOnly(true); handler.getSessionCookieConfig().setSecure(true); staticContext.setSessionHandler(handler); - staticContext.addAliasCheck(new AllowSymLinkAliasChecker()); + staticContext.addAliasCheck(new SymlinkAllowedResourceAliasChecker(staticContext)); setContextAttributes(staticContext, conf); defaultContexts.put(staticContext, true); } diff --git a/hadoop-project/pom.xml b/hadoop-project/pom.xml index 72504c1825e90..91aa59f9a8feb 100644 --- a/hadoop-project/pom.xml +++ b/hadoop-project/pom.xml @@ -37,7 +37,7 @@ true true - 9.4.44.v20210927 + 9.4.48.v20220622 _ _