Uploaded image for project: 'Apache Avro'
  1. Apache Avro
  2. AVRO-3656

Vulnerabilities from dependencies - jackson-databind & commons-text

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • 1.11.1
    • 1.12.0, 1.11.2
    • None
    • None

    Description

      Version 1.11.1 of avro-compiler contains the apache commons-text vulnerable library (1.9)  & 

      Jackson-databind (2.12.7)

       

      Vulnerabilities from dependencies:
      CVE-2022-42889
      CVE-2022-42004
      CVE-2022-42003

       

      Is there any plan to upgrade dependency and address this issue?

      Attachments

        Activity

          People

            mgrigorov Martin Tzvetanov Grigorov
            Ragul96 Ragul
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: