Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[security] Upgrade jackson-databind #5011

Merged
merged 1 commit into from Aug 22, 2019

Conversation

massakam
Copy link
Contributor

Motivation

Currently, jackson-databind in the Pulsar distribution has a security vulnerability and should be upgraded to the latest version.
https://nvd.nist.gov/vuln/detail/CVE-2019-14379

Modifications

Upgraded the version of jackson-databind to 2.9.9.3. However, only jackson-databind used in pulsar-sql is 2.8.11.4 (cf. #2978).

@massakam massakam added this to the 2.4.1 milestone Aug 22, 2019
@massakam massakam self-assigned this Aug 22, 2019
@jiazhai jiazhai requested review from sijie and merlimat August 22, 2019 12:06
@merlimat merlimat merged commit ee158d9 into apache:master Aug 22, 2019
@massakam massakam deleted the upgrade-jackson-databind branch August 23, 2019 02:01
jiazhai pushed a commit that referenced this pull request Aug 28, 2019
(cherry picked from commit ee158d9)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants