Skip to content
This repository has been archived by the owner on Jan 31, 2025. It is now read-only.

Vulnerabilities in Jackson Mapper ASL used by Jet master #3016

Open
olukas opened this issue Apr 8, 2021 · 1 comment
Open

Vulnerabilities in Jackson Mapper ASL used by Jet master #3016

olukas opened this issue Apr 8, 2021 · 1 comment
Labels
security Pull requests that address a security vulnerability severity:critical Vulnerability scan classification for Critical Severity issues

Comments

@olukas
Copy link
Collaborator

olukas commented Apr 8, 2021

Jet hazelcast-jet-files-azure uses Jackson Mapper ASL 1.9.13 which includes following vulnerabilities:

It is the same issue as in #2913 however hazelcast-jet-files-azure was not part of 4.3.x hence it seems we forget to apply the changes also to this module.

@olukas olukas added security Pull requests that address a security vulnerability severity:critical Vulnerability scan classification for Critical Severity issues labels Apr 8, 2021
@olukas olukas added this to the 4.5 milestone Apr 8, 2021
@gurbuzali
Copy link

hazelcast-jet-files-azure depends on org.apache.hadoop:hadoop-azure:jar:3.3.0 which depends on org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13. we use latest version for hadoop-azure and the mentioned fixed version (1.9.13-2) is not available in maven-central. the library is moved to com.fasterxml.jackson.core:jackson-databind, that's why it is not in the maven-central most probably.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
security Pull requests that address a security vulnerability severity:critical Vulnerability scan classification for Critical Severity issues
Projects
None yet
Development

No branches or pull requests

4 participants