Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
shaded-9.0, shaded-10.0, shaded-11.0, shaded-12.0
Description
Our current Jackson version (2.10.1) is vulnerable for at least this CVE:
https://nvd.nist.gov/vuln/detail/CVE-2020-25649
Bump it to 2.10.5.1+ should address this issue.
Attachments
Issue Links
- is duplicated by
-
FLINK-21544 Upgrade Jackson databind version from 2.10.1 used in, at least, Flink Python jar
- Closed
- relates to
-
FLINK-21152 Bump flink-shaded to 13.0
- Closed
- links to
(1 links to)