Skip to content

Conversation

@beliefer
Copy link
Collaborator

@beliefer beliefer commented Nov 8, 2019

What changes were proposed in this pull request?

The current code uses com.fasterxml.jackson.core:jackson-databind:jar:2.9.10 and it will cause a security vulnerabilities.
We referenced GHSA-mx7p-6679-8g3q
This Alert remind to upgrate the version of jackson-databind to 2.9.10.1 or later.
I referenced Spark 3.0.0 contains jackson-databind:jar:2.10.0.

How was this patch tested?

No UT now.

@beliefer beliefer added the security Security vulnerabilities. label Nov 11, 2019
@wenfang6
Copy link
Collaborator

LGTM

@wenfang6
Copy link
Collaborator

Thanks! Merged to master and branch-0.6

@wenfang6 wenfang6 closed this Nov 18, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security vulnerabilities.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants