Details
Description
New RCE found in jackson-databind 2.0.0 through 2.9.10.2.
Patched in 2.9.10.3. Looks critical.
After HADOOP-16882 get in we should backport this to those lower-version branches ASAP.
Attachments
Issue Links
- is duplicated by
-
HADOOP-16883 update jackon-databind version
- Resolved
- is related to
-
HADOOP-16485 Remove dependency on jackson
- Open
- links to