Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
1.17.0
-
None
-
None
Description
Vulnerabilities in dependency htrace-core4-4.1.0-incubating.jar (shaded: com.fasterxml.jackson.core:jackson-databind:2.4.0)
Max CVSS Score: 9.8 (Critical)
Total # CVEs: 20
Note: The issue with htrace is its use of Jackson Databind.
Are these vulnerabilities exploitable from Apache Drill?