Fixed CVEs
Common Vulnerabilities and Exposures (CVE) that are addressed in this release are mentioned in the following table:
Apache JIRA | Description |
|---|---|
AMBARI-25717 | Fixed broken build on branch-2.7. |
AMBARI-25714 | Upgraded commons-compress to 1.21 to resolve CVEs. |
AMBARI-25715 | Upgraded ant to 1.10.11 to resolve CVEs. |
AMBARI-25713 | Upgrade commons-io to 2.8.0 to resolve CVEs. |
AMBARI-25716 | Upgraded Httpclient to 4.5.13 to resolve CVEs. |
AMBARI-25725 | Upgraded bootstrap.min.js to resolve CVEs. |
AMBARI-25785 | Upgraded jackson-databind to resolve CVEs. |
AMBARI-25808 | Fixed issue where metrics data simulator was throwing NPE. |
AMBARI-25947 | Fixed syntax error in ambari-metrics-host-monitoring/..../emitter.py |
AMBARI-25962 | Fixed issue where host apps metadata was not getting synced to other collectors when multiple collectors were installed. |
AMBARI-25963 | Resolved metrics metadata sync problem, while accessing metrics which was created though other collectors throwing NPE. |
AMBARI-25984 | Resolved Ambari metrics summary API missing daily aggregator information. |
AMBARI-25998 | Fixed Issue where host uuid was not getting synced to other collectors, causing NPE while accessing metrics. |
Fixed Ambari Spoofing Vulnerability | |
Fixed xss vulnerability. Contributed by Nikhil Daf | |
Validated xml file to remediate vulnerability. Contributed by Bhavya Hoda | |
Update the KEYS File |
