Skip to content

Commit 3baa288

Browse files
authored
HADOOP-19632. Upgrade nimbus-jose-jwt to 10.4 (#7965)
Addresses CVE-2025-53864 Contributed by Rohit Kumar
1 parent f3cd00d commit 3baa288

File tree

5 files changed

+23
-3
lines changed

5 files changed

+23
-3
lines changed

LICENSE-binary

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -269,7 +269,7 @@ com.google.http-client:google-http-client:1.46.3
269269
com.google.j2objc:j2objc-annotations:3.0.0
270270
com.google.oauth-client:google-oauth-client:1.37.0
271271
com.microsoft.azure:azure-storage:7.0.0
272-
com.nimbusds:nimbus-jose-jwt:9.37.2
272+
com.nimbusds:nimbus-jose-jwt:10.4
273273
com.zaxxer:HikariCP:4.0.3
274274
commons-beanutils:commons-beanutils:1.9.4
275275
commons-cli:commons-cli:1.9.0

hadoop-project/pom.xml

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -245,7 +245,8 @@
245245
<openssl-wildfly.version>2.1.4.Final</openssl-wildfly.version>
246246
<jsonschema2pojo.version>1.0.2</jsonschema2pojo.version>
247247
<woodstox.version>5.4.0</woodstox.version>
248-
<nimbus-jose-jwt.version>9.37.2</nimbus-jose-jwt.version>
248+
<nimbus-jose-jwt.version>10.4</nimbus-jose-jwt.version>
249+
<jcip-annotations.version>1.0-1</jcip-annotations.version>
249250
<nodejs.version>v12.22.1</nodejs.version>
250251
<yarnpkg.version>v1.22.5</yarnpkg.version>
251252
<apache-ant.version>1.10.13</apache-ant.version>
@@ -1551,6 +1552,11 @@
15511552
<artifactId>jsr305</artifactId>
15521553
<version>3.0.2</version>
15531554
</dependency>
1555+
<dependency>
1556+
<groupId>com.github.stephenc.jcip</groupId>
1557+
<artifactId>jcip-annotations</artifactId>
1558+
<version>${jcip-annotations.version}</version>
1559+
</dependency>
15541560
<dependency>
15551561
<groupId>jakarta.xml.bind</groupId>
15561562
<artifactId>jakarta.xml.bind-api</artifactId>

hadoop-tools/hadoop-sls/pom.xml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,11 @@
9393
<artifactId>junit-platform-launcher</artifactId>
9494
<scope>test</scope>
9595
</dependency>
96+
<dependency>
97+
<groupId>com.github.stephenc.jcip</groupId>
98+
<artifactId>jcip-annotations</artifactId>
99+
<scope>test</scope>
100+
</dependency>
96101
</dependencies>
97102

98103
<build>

hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-resourcemanager/pom.xml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -354,6 +354,11 @@
354354
<artifactId>junit-platform-launcher</artifactId>
355355
<scope>test</scope>
356356
</dependency>
357+
<dependency>
358+
<groupId>com.github.stephenc.jcip</groupId>
359+
<artifactId>jcip-annotations</artifactId>
360+
<scope>test</scope>
361+
</dependency>
357362
</dependencies>
358363

359364
<build>

hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-router/pom.xml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -168,7 +168,11 @@
168168
<artifactId>assertj-core</artifactId>
169169
<scope>test</scope>
170170
</dependency>
171-
171+
<dependency>
172+
<groupId>com.github.stephenc.jcip</groupId>
173+
<artifactId>jcip-annotations</artifactId>
174+
<scope>test</scope>
175+
</dependency>
172176
</dependencies>
173177

174178
<build>

0 commit comments

Comments
 (0)