Fixed CVEs
This release resolves 1100+ security vulnerabilities (CVEs) identified across ODP platform components in addition to CVEs addressed in individual Apache project upgrades. Thus, represents a comprehensive security hardening initiative implemented during the upgrade from version 3.2.3.3-2 to 3.2.3.4-2.
Detailed List of CVEs Addressed
For detailed information about CVEs addressed in this release, see ODP 3.2.3.4-3 Acceldata Open-Source Data Platform CVE Fixes.
Summary of CVEs by component and severity level
You can see the summary of CVEs addressed by components and severity level.
Component | Critical 🔴 | High 🟠 | Total |
|---|---|---|---|
cruise-control | 2 | 3 | 5 |
cruise-control3 | 1 | 3 | 4 |
druid | 4 | 11 | 15 |
hadoop | 10 | 47 | 57 |
hbase | 2 | 3 | 5 |
hive | 36 | 125 | 161 |
hue | 1 | 2 | 3 |
impala | 20 | 72 | 92 |
jupyterhub | 1 | 3 | 4 |
kafka | 2 | 22 | 24 |
kafka3 | 2 | 15 | 17 |
knox | 8 | 22 | 30 |
kudu | 0 | 16 | 16 |
livy2 | 0 | 4 | 4 |
livy3 | 0 | 4 | 4 |
nifi | 1 | 7 | 8 |
oozie | 54 | 166 | 220 |
ozone | 2 | 15 | 17 |
phoenix | 1 | 0 | 1 |
pinot | 5 | 9 | 14 |
ranger | 23 | 45 | 68 |
registry | 27 | 58 | 85 |
spark2 | 4 | 39 | 43 |
spark3 | 2 | 4 | 6 |
sqoop | 2 | 1 | 3 |
tez | 10 | 42 | 52 |
trino | 3 | 6 | 9 |
zeppelin | 38 | 87 | 125 |
zookeeper | 1 | 9 | 10 |
Total | 262 | 840 | 1102 |
