Skip to content

Fix CVE-2021-25646#10818

Merged
jihoonson merged 3 commits intoapache:masterfrom
jihoonson:fix-javascript
Feb 4, 2021
Merged

Fix CVE-2021-25646#10818
jihoonson merged 3 commits intoapache:masterfrom
jihoonson:fix-javascript

Conversation

@jihoonson
Copy link
Copy Markdown
Contributor

@jihoonson jihoonson commented Jan 29, 2021

Description

This PR fixes CVE-2021-25646.


This PR has:

  • been self-reviewed.
  • added documentation for new or modified features or behaviors.
  • added Javadocs for most classes and all non-trivial methods. Linked related entities via Javadoc links.
  • added or updated version, license, or notice information in licenses.yaml
  • added comments explaining the "why" and the intent of the code wherever would not be obvious for an unfamiliar reader.
  • [ x added unit tests or modified existing tests to cover new code paths, ensuring the threshold for code coverage is met.
  • added integration tests.
  • been tested in a test Druid cluster.

@jihoonson jihoonson added this to the 0.21.0 milestone Jan 29, 2021
@jihoonson
Copy link
Copy Markdown
Contributor Author

The Travis failure is #10853. I'm not sure why it keeps failing on Travis as it runs successfully on my local. I'm going to merge this PR as it is a release blocker for 0.21.0.

@jihoonson jihoonson merged commit 3f8f00a into apache:master Feb 4, 2021
jihoonson added a commit to jihoonson/druid that referenced this pull request Feb 4, 2021
jihoonson added a commit that referenced this pull request Feb 4, 2021
jon-wei added a commit to jon-wei/druid that referenced this pull request Feb 11, 2021
* move integration tests from ZooKeeper 3.4.x to 3.5.x (apache#10786)

* move integration tests from ZooKeeper 3.4.x to 3.5.x
* run a subset of our integration tests with ZK 3.4 for backwards compatibility testing.
* remove need to build separate docker-base image
- use multi-stage build for the base image
- use openjdk base image instead of building our own JDK base
- workaround Debian not including MySQL by using MariaDB
- download mysql connector directly instead of using distro version
* fix incorrect openssl command failing on Debian
* keep mysql connector version in sync with pom version

* K8s IT Test enhance  (apache#10785)

* do build and stop action in IT

* change base dir from druidHome to druidHome/integration-tests

* add env DRUID_HOME

* bug fix

* modify stop_sh

* ready to test

* bug fix

* modify dir

* tested on dev

* modify dir

* move DRUID_HOME env

* done

Co-authored-by: yuezhang <yuezhang@freewheel.tv>

* Update NOTICE copyright year (apache#10834)

the future is now

* Cleanup openssl fixes to keep certs

* Address CVE-2020-8570, suppress CVE-2020-8554 (apache#10826)

* Address CVE-2020-8570, suppress CVE-2020-8554

* Update licenses.yaml

* wget debug

* Suppress CVE-2020-9492 for hadoop-mapreduce-client-core (apache#10847)

* Revert "wget debug"

This reverts commit 5b81c33b4728420e2312b3c919b7de9c1b4da589.

* Add MYSQL_VERSION env variable in integration-tests-imply tests

* Increase heap to 64m for custom node (apache#10846)

* Fix CVE-2021-25646 (apache#10818)

* Add ZK_VERSION env variable

Co-authored-by: Xavier Léauté <xvrl@apache.org>
Co-authored-by: zhangyue19921010 <69956021+zhangyue19921010@users.noreply.github.com>
Co-authored-by: yuezhang <yuezhang@freewheel.tv>
Co-authored-by: Clint Wylie <cwylie@apache.org>
Co-authored-by: Slava Mogilevsky <triggerwoods91@gmail.com>
Co-authored-by: Jihoon Son <jihoonson@apache.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants