Uploaded image for project: 'Kafka'
  1. Kafka
  2. KAFKA-13775

CVE-2020-36518 - Upgrade jackson-databind to 2.12.6.1

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 3.1.0, 3.0.0, 3.0.1
    • 3.2.0, 3.1.1
    • None

    Description

      CVE-2020-36518 vulnerability affects Jackson-Databind in Kafka (see https://github.com/advisories/GHSA-57j2-w4cx-62h2).

      Upgrading to jackson-databind version 2.12.6.1 should address this issue.

      Attachments

        Issue Links

          Activity

            People

              edwin092 Edwin Hobor
              edwin092 Edwin Hobor
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: