Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-19230

upgrade to jackson 2.14.3

    XMLWordPrintableJSON

Details

    • Task
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • common

    Description

      Follow up to HADOOP-18332

      I have what I believe fixes the Jackson JAX-RS incompatibility.

      https://github.com/pjfanning/jsr311-compat/

      The reason that I want to start by just going to Jackson 2.14 is that Jackson has new StreamReadConstraints in Jackson 2.15 to protect against malicious JSON inputs. The constraints are generous but can cause issues with very large or deeply nested inputs.

      Jackson has had a lot of security hardening fixes recently and it seems problematic to be stuck on an unsupported version of Jackson (2.12).

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              fanningpj PJ Fanning
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated: