Skip to content

Conversation

eschcam
Copy link
Contributor

@eschcam eschcam commented Oct 7, 2025

What changes were proposed in this pull request?

Upgrade commons-lang3 to 3.19.0

Why are the changes needed?

Commons-lang3 3.12.0 contains CVE-2025-48924

Does this PR introduce any user-facing change?

No

How was this patch tested?

Passed CI tests

Was this patch authored or co-authored using generative AI tooling?

No

@github-actions github-actions bot added the BUILD label Oct 7, 2025
Copy link
Member

@dongjoon-hyun dongjoon-hyun left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To @eschcam , when it comes to backport, you need to verify that CVE is really meaningful for the users.

I don't think the Apache Spark is affected because we don't use org.apache.commons.lang3.ClassUtils.getClass method's CVE bug.

Commons-lang3 3.12.0 contains GHSA-j288-q9x7-2f5v

Please provide more reasons for justification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants