Uploaded image for project: 'Ignite'
  1. Ignite
  2. IGNITE-13601

Ignite-rest-http and ignite-kubernetes include vulnerable dependencies

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Blocker
    • Resolution: Fixed
    • 2.8.1
    • None
    • rest
    • Docs Required, Release Notes Required

    Description

      The ignite-rest-http and ignite-kubernetes modules include a vulnerable version of the jackson-databind library. This was spotted in 2.8.1.

      This component jackson-databind-2.9.6.jar is flagged as having numerous
      critical, high and medium security vulnerabilities, one of which is
      described here:
      https://nvd.nist.gov/vuln/detail/CVE-2019-14540

      More here:

      http://apache-ignite-users.70518.x6.nabble.com/Critical-security-vulnerability-for-opt-ignite-apache-ignite-libs-optional-ignite-rest-http-jackson-r-td34032.html

       

      Attachments

        Issue Links

          Activity

            People

              igorb Igor Baryshnikov
              andrewstory Andrew Story
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 40m
                  40m