Uploaded image for project: 'HBase'
  1. HBase
  2. HBASE-27423

Upgrade hbase-thirdparty to 4.1.3 and upgrade Jackson for CVE-2022-42003/42004

    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      Jackson 2.13.4 fixes CVE-2022-42003 and databind 2.14.0-rc1 fixes CVE-2022-42004.

      Move jackson.version to 2.13.4.
      Move jackson.databind.version to 2.14.0-rc1.

      Attachments

        Issue Links

          Activity

            People

              zhangduo Duo Zhang
              apurtell Andrew Kyle Purtell
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: